Skip to content
Palo Alto NetworksCVE-2026-0285

Palo Alto Networks PAN-OS: server-side request forgery

Medium4.7CVE-2026-0285 · Published Jul 9, 2026 · updated Aug 11, 2026

A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with network access to the management web interface to make unauthorized requests from the firewall to internal services. The security risk posed by this issue is minimized when the management interface is restricted to only trusted internal IP addresses according to our recommended  best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .  Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

Palo Alto Networks advisory

Affected versions

PackageAffectedFixed in
PAN-OS
Product
>= 12.1.0, < 12.1.812.1.8
>= 11.2.0, < 11.2.1311.2.13
>= 11.1.0, < 11.1.1611.1.16
>= 10.2.0, < 10.2.18-h810.2.18-h8
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-918

More Palo Alto Networks advisories

All Palo Alto Networks
Advisory
Palo Alto Networks Prisma Browser: privilege escalation
Low2.0Jul 9
Palo Alto Networks Cortex XDR Broker VM: privilege escalation
Low1.1Jul 9
Palo Alto Networks Prisma Access Agent: improper certificate validation
Medium5.7Jul 9
Palo Alto Networks Prisma: local user could bypass DLP policy enforcement...
Medium5.8Jul 9
Palo Alto Networks PAN-OS: command injection
Medium6.0Jul 9
Palo Alto Networks Cloud NGFW: denial of service
Medium6.6Jul 9

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.