← All Advisories

CVE-2026-0284

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-0284

Key Details

CVECVE-2026-0284
CVSS Score / Version9.9 (Critical) / CVSS v3.1
Updated2026-08-11
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is low; availability impact is low.
Affected productsPalo Alto Networks PAN-OS and Siemens RUGGEDCOM APE1808
Classified asCWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Palo Alto NetworksPAN-OS
SiemensRUGGEDCOM APE1808
SubsystemsGeneral OT
SectorsMulti-sector

What to Know

An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data.

Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability. (NVD)

What to Do

Monitor Palo Alto Networks's and Siemens's web pages for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-0284
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-0284
Vendor advisoryhttps://security.paloaltonetworks.com/CVE-2026-0284