VYPR
advisoryPublished Jul 21, 2026· 1 source

Multiple Vulnerabilities Discovered in Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW

CISA has issued an advisory detailing three critical vulnerabilities in Siemens RUGGEDCOM APE1808 devices running Palo Alto Networks Virtual NGFW, potentially allowing authenticated administrators to escalate privileges and inject commands.

The Cybersecurity and Infrastructure Security Agency (CISA) has released an advisory detailing multiple vulnerabilities affecting Siemens RUGGEDCOM APE1808 devices when integrated with Palo Alto Networks Virtual NGFW. These vulnerabilities, identified as CVE-2026-0266, CVE-2026-0272, and CVE-2026-0273, pose significant risks to critical infrastructure sectors, particularly in manufacturing, and have been observed deployed globally.

CVE-2026-0266 is a cross-site scripting (XSS) vulnerability. It allows a malicious authenticated administrator to inject and store a JavaScript payload through the web interface. This flaw is applicable to PAN-OS software on PA-Series and VM-Series firewalls, as well as Panorama virtual and M-Series appliances. While the CVSS score for this vulnerability is low (2.4), XSS can be a stepping stone for more complex attacks or for phishing within an organization.

CVE-2026-0272 addresses a privilege escalation vulnerability within Palo Alto Networks' PAN-OS software. An authenticated administrator with Command Line Interface (CLI) access can exploit this flaw to gain root privileges on the affected device. The advisory notes that the risk is mitigated by restricting CLI access to a limited group of administrators and securing the management interface, aligning with Palo Alto Networks' best practices.

CVE-2026-0273 is a command injection vulnerability that enables an authenticated administrator to bypass system restrictions and execute arbitrary commands with root privileges. This exploit can be performed via the PAN-OS CLI or its web interface. Similar to the privilege escalation flaw, restricting access to the management interface and CLI is crucial for mitigating this high-severity (CVSS 7.2) vulnerability.

All three vulnerabilities are applicable to PAN-OS software running on PA-Series and VM-Series firewalls, and Panorama appliances. Notably, Cloud NGFW and Prisma Access are not affected by these specific issues. The affected Siemens product is the RUGGEDCOM APE1808, with all versions listed as known affected when running the vulnerable Palo Alto Networks Virtual NGFW.

Siemens advises customers to contact their support channels to obtain the necessary patches and update information. The company also emphasizes the importance of protecting network access to devices and configuring environments according to Siemens' operational guidelines for Industrial Security. Customers are directed to consult Palo Alto Networks' upstream security notifications for workarounds and further details.

These vulnerabilities highlight the complex security challenges in converged environments where multiple vendors' products are integrated. The reliance on authenticated administrator access for exploitation underscores the importance of robust access control and credential management practices within industrial control systems and critical infrastructure networks.

Synthesized by Vypr AI