Skip to content
All vulnerabilities
CVE-2026-0259

WildFire WF-500 and WF-500-B: Arbitrary File Read and Delete Vulnerability in WildFire Appliance (WF-500, WF-500-B)

Severity
High8.8CVSS 3.1, High
EPSS
0.34%
Published
13 May 2026
Updated
14 Jul 2026

Description

Title, description and vendor guidance are quoted from the source records.

An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables users to read sensitive information and delete arbitrary files. This vulnerability affects WF-500 and WF-500-B appliances running in the default non-FIPS configuration mode. The WildFire Appliance (WF-500, WF-500-B) software update is now available to customers that use the WildFire Appliance (WF-500, WF-500-B) for on-premise sandboxing. Please note that customers using the WildFire Public cloud service are NOT impacted by this vulnerability.

Weakness: CWE-73

Known exploited

Not listed in CISA KEV as of the last check.

Exploit prediction

0.34% probability of exploitation in the next 30 days (percentile 24%).

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

Patcharo shows this vulnerability for information but does not match versions for this product yet.

  • Palo Alto Networks WildFire WF-500 and WF-500-B · 12.1.0 < 12.1.7, 12.1.4-h5, 11.2.0 < 11.2.11,11.2.7-h7, 11.1.0 < 11.1.13,11.1.10-h8, 10.2.0 < 10.2.18-h6, 10.2.16-h7, 10.2.13-h21, 10.2.10-h36, 10.2.7-h34

References

Provenance

Every fact on this page comes from the sources below. Nothing is written by an AI.

Palo Alto Networks (CVE record)
Palo Alto Networks (CVE record) · 27 Sept 2026, 23:46 UTC · Parser patcharo-cve5/1.1.0
NVD
NVD · 27 Sept 2026, 23:44 UTC · Parser patcharo-nvd/1.0.0
FIRST EPSS
FIRST EPSS · 27 Sept 2026, 23:46 UTC · Parser patcharo-epss/1.0.0

Last verified: 28 Sept 2026, 02:31 UTC