CVE-2026-0258
CVE-2026-0258: 1 tracked advisory record across Palo Alto. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Palo Alto
1 advisory- Advisory severityHigh8.3
High [CVE-2026-0258] PAN-OS: Server-Side Request Forgery (SSRF) in IKEv2 Certificate URL Fetching
CVE-2026-0258Source published
CVE-2026-0258 PAN-OS: Server-Side Request Forgery (SSRF) in IKEv2 Certificate URL Fetching
- Affected products in this advisory
- PAN-OS
- Source-reported affected versions
- PAN-OS 12.1: < 12.1.4-h5< 12.1.7
- PAN-OS 11.2: < 11.2.4-h17< 11.2.7-h13< 11.2.10-h6< 11.2.12
- PAN-OS 11.1: < 11.1.4-h33< 11.1.6-h32< 11.1.7-h6< 11.1.10-h25< 11.1.13-h5< 11.1.15
- PAN-OS 10.2: < 10.2.7-h34< 10.2.10-h36< 10.2.13-h21< 10.2.16-h7< 10.2.18-h6
- Source-reported fixed versions
- PAN-OS >= 12.1.4-h5
- PAN-OS >= 12.1.7
- PAN-OS >= 11.2.4-h17
- PAN-OS >= 11.2.7-h13
13 more entries in the full advisory.
- Mitigation guidance
- All older unsupported PAN-OS versions Upgrade to a supported fixed version.
- Workarounds
- Customers who do not require IKEv2 VPN can mitigate this issue by removing all IKEv2 VPN gateway configurations.
- Customers with a Threat Prevention subscription can block attacks for this vulnerability by enabling Threat ID 510014 (from Applications and Threats content version 9100-10044).
Android app · Google Play
Monitor future Palo Alto CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.