Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-0285

CVE-2026-0285: 1 tracked advisory record across Palo Alto. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Palo Alto

1 advisory
  • Advisory severityHigh7.0

    High [CVE-2026-0285] PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface

    CVE-2026-0285Source published

    A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with network access to the management web interface to make unauthorized requests from the firewall to internal services. The security risk posed by this issue is minimized when the management interface is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

    Affected products in this advisory
    • PAN-OS
    Source-reported affected versions
    • PAN-OS < 12.1.8
    • PAN-OS < 11.2.13
    • PAN-OS < 11.1.16
    • PAN-OS < 10.2.18-h8
    Source-reported fixed versions
    • PAN-OS >= 12.1.8
    • PAN-OS >= 12.1.7-h2
    • PAN-OS >= 12.1.4-h8
    • PAN-OS >= 11.2.13

    14 more entries in the full advisory.

    Mitigation guidance
    • VersionMinor VersionSuggested SolutionCloud NGFWNo action needed.
    • PAN-OS 12.1 12.1.5 through 12.1.7-h* Upgrade to 12.1.7-h2 or 12.1.8 or later. 12.1.2 through 12.1.4-h* Upgrade to 12.1.4-h8 or 12.1.8 or later.
    Workarounds
    • The vast majority of firewalls already follow Palo Alto Networks' and industry best practices.
    • However, if you have not already, we strongly recommend that you secure access to your management interface according to our best practice deployment guidelines.
    • Specifically, you should restrict management interface access to only trusted internal IP addresses.
    • Review information about how to secure management access to your Palo Alto Networks firewalls:

    3 more entries in the full advisory.

Android app · Google Play

Monitor future Palo Alto CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery