PALO ALTO Security Advisory

Published Date: July 8, 2026

CVE: CVE-2026-0285

Advisory Summary

🔔 Security Alert: Medium Severity SSRF Vulnerability in PAN-OS Management Interface

Palo Alto Networks has disclosed a Server-Side Request Forgery (SSRF) vulnerability identified as CVE-2026-0285 in the PAN-OS management web interface. This medium-severity issue could allow an attacker to manipulate server requests through the management interface, potentially enabling unauthorized access to internal services or data. While the risk level is moderate, organizations relying on Palo Alto’s PAN-OS should prioritize evaluating their exposure and promptly apply the available security updates.

Given the management interface’s critical role in firewall operation and network security controls, this vulnerability underscores the need for regular patching and monitoring of access controls. IT infrastructure teams should ensure their Palo Alto firewalls are running the patched PAN-OS versions and review firewall access policies to mitigate exploitation risks.

Stay vigilant as SSRF vulnerabilities can serve as stepping stones for deeper network compromises, especially when combined with other security gaps.

Reference: Vendor Advisory