CVE-2026-0259

HIGH

An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables users to read sensitive information and delete arbitrary files. This vulnerabi...

Affects 0 products across 4 vendors.

BCS3.35
CVSS 3.18.8
CVSS v45.0
EPSS0.3%
Percentile26th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, low privileges required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-73: CWE-73
Related Attack Patterns (CAPEC)
CAPEC-13 Subverting Environment Variable Values
via CWE-73
CAPEC-64 Using Slashes and URL Encoding Combined to Bypass Validation Logic
via CWE-73
CAPEC-72 URL Encoding
via CWE-73
CAPEC-76 Manipulating Web Input to File System Calls
via CWE-73
CAPEC-78 Using Escaped Slashes in Alternate Encoding
via CWE-73
Show all 8
via CWE-73
via CWE-73
via CWE-73

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A low severity vulnerability affects Cloud systems (CVE-2026-0259). No public exploit code is currently available. Review vendor advisories and apply patches during the next maintenance window.

BSID: BS-2026-GLOBAL-059149-I • Model: rule-based-v1 • Confidence: LOW

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-0259?
A low severity vulnerability affects Cloud systems (CVE-2026-0259). No public exploit code is currently available. Review vendor advisories and apply patches during the next maintenance window.
What is the CVSS score for CVE-2026-0259?
CVE-2026-0259 has CVSS 8.8 (High). Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.3%.
Is CVE-2026-0259 actively exploited?
No confirmed active exploitation of CVE-2026-0259 as of 2026-07-15.
How do I remediate CVE-2026-0259?
Priority: MONITOR. PSIRT: [email protected]
What systems are affected by CVE-2026-0259?
CVE-2026-0259 affects: Cloud, Files, Palo Alto, Palo Alto Networks.
Vulnerability Details
CVE IDCVE-2026-0259
BSIDBS-2026-GLOBAL-059149-I BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Published2026-05-13
Last Modified2026-07-14
ICS Relevance55%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables users to read sensitive information and delete arbitrary files. This vulnerability affects WF-500 and WF-500-B appliances running in the default non-FIPS configuration mode. The WildFire Appliance (WF-500, WF-500-B) software update is now available to customers that use the WildFire Appliance (WF-500, WF-500-B) for on-premise sandboxing. Please note that customers using the WildFire Public cloud service are NOT impacted by this vulnerability.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables users to read sensitive information and delete arbitrary files. This vulnerability affects WF-500 and WF-500-B appliances running in the default non-FIPS configuration mode. The WildFire Appliance (WF-500, WF-500-B) software update is now available to customers that use the WildFire Appliance (WF-500, WF-500-B) for on-premise sandboxing. Please note that customers using th CVSS vector: Not available.

Exploitation Likelihood: MINIMAL

Affected Products
VendorProductFixed Version
Cloud —
Files —
Palo Alto —
Palo Alto Networks —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 73 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceLOW
Enriched At2026-05-24
SHA-512 Audit Hash19bba6ab054b2bdd15c8fc170ab58918224bff0ba3fcd496b0aa31c7aaefcff4990036484ca64cb34ea52440015e2b055f9b349fa16328c44090f753870aae61
Related CVEs affecting Cloud
CVE-2025-54122 10.0 Manager-io/Manager is accounting software. A critical unauthenticated full re... CVE-2025-41243 10.0 Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment p... CVE-2025-64180 10.0 Manager-io/Manager is accounting software. In Manager Desktop and Server vers... CVE-2026-0501 9.9 Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Prem... CVE-2025-47282 9.9 Gardener External DNS Management is an environment to manage external DNS ent...
View all Cloud CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →