CVE-2026-0258: PAN-OS: Server-Side Request Forgery (SSRF) in IKEv2 Certificate URL Fetching
A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send network requests to unintended destinations or cause a denial of service (DoS) condition.
Panorama, Cloud NGFW and Prisma® Access are not impacted by these vulnerabilities.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.4-h5Fixed in 12.1.7Fixed in 11.2.4-h17Fixed in 11.2.7-h13Fixed in 11.2.10-h6Fixed in 11.2.12Fixed in 11.1.4-h33Fixed in 11.1.6-h32Fixed in 11.1.7-h6Fixed in 11.1.10-h25Fixed in 11.1.13-h5Fixed in 11.1.15Fixed in 10.2.7-h34Fixed in 10.2.10-h36Fixed in 10.2.13-h21Fixed in 10.2.16-h7Fixed in 10.2.18-h6 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.7-h34 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.18-h6 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.13-h21 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.16-h7 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 10.2.10-h36 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.4-h33 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.15 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.13-h5 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.6-h32 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.7-h6 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.1.10-h25 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.4-h17 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.12 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.7-h13 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 11.2.10-h6 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 12.1.4-h5 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 12.1.7 - Upgrade
Upgrade
Palo Alto Networks PAN-OSto a version that resolves this vulnerability.Fixed in 12.1.5 - Configuration
If you do not require IKEv2 VPN, remove all IKEv2 VPN gateway configurations to mitigate the IKEv2 SSRF vulnerability.
Palo Alto Networks PAN-OS IKEv2 VPN gateway configuration IKEv2 VPN gateway configurations = remove all IKEv2 VPN gateway configurations (if IKEv2 VPN is not required) - Configuration
If you have a Threat Prevention subscription, enable Threat ID 510014 from Applications and Threats content version 9100-10044 to block attacks for this vulnerability.
Palo Alto Networks Threat Prevention subscription Threat ID = 510014 (enable)
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0258?
The severity of CVE-2026-0258 is classified as MEDIUM.
How do I fix CVE-2026-0258?
To fix CVE-2026-0258, upgrade your PAN-OS to versions 12.1.4-h5, 12.1.7, 11.2.4-h17, 11.2.7-h13, 11.2.10-h6, 11.2.12, or other specified remedial versions.
What type of vulnerability is CVE-2026-0258?
CVE-2026-0258 is a Server-Side Request Forgery (SSRF) vulnerability.
Who is affected by CVE-2026-0258?
CVE-2026-0258 affects users of Palo Alto Networks' PAN-OS, Cloud NGFW, and Prisma Access.
Can CVE-2026-0258 be exploited by unauthenticated users?
Yes, CVE-2026-0258 can be exploited by unauthenticated attackers.