CVE-2026-0259
Published: May 13, 2026
Modified: May 13, 2026
Description
An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables users to read sensitive information and delete arbitrary files. This vulnerability affects WF-500 and WF-500-B appliances running in the default non-FIPS configuration mode. The WildFire Appliance (WF-500, WF-500-B) software update is now available to customers that use the WildFire Appliance (WF-500, WF-500-B) for on-premise sandboxing. Please note that customers using the WildFire Public cloud service are NOT impacted by this vulnerability.
| Vendor | Product | Versions |
|---|---|---|
Palo Alto Networks | WildFire WF-500 and WF-500-B | affected 12.1.0 - < 12.1.7, 12.1.4-h5affected 11.2.0 - < 11.2.11,11.2.7-h7affected 11.1.0 - < 11.1.13,11.1.10-h8affected 10.2.0 - < 10.2.18-h6, 10.2.16-h7, 10.2.13-h21, 10.2.10-h36, 10.2.7-h34 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now