CVE-2026-0259: WildFire WF-500 and WF-500-B: Arbitrary File Read and Delete Vulnerability in WildFire Appliance (WF-500, WF-500-B)
An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables users to read sensitive information and delete arbitrary files. This vulnerability affects WF-500 and WF-500-B appliances running in the default non-FIPS configuration mode.
The WildFire Appliance (WF-500, WF-500-B) software update is now available to customers that use the WildFire Appliance (WF-500, WF-500-B) for on-premise sandboxing.
Please note that customers using the WildFire Public cloud service are NOT impacted by this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.7Fixed in 12.1.4-h5Fixed in 11.2.12Fixed in 11.2.10-h6Fixed in 11.2.7-h13Fixed in 11.2.4-h17Fixed in 11.1.15Fixed in 11.1.13-h5Fixed in 11.1.10-h25Fixed in 11.1.7-h6Fixed in 11.1.6-h32Fixed in 11.1.4-h33Fixed in 10.2.18-h6Fixed in 10.2.16-h7Fixed in 10.2.13-h21Fixed in 10.2.10-h36Fixed in 10.2.7-h34 - Upgrade
Upgrade
Palo Alto Networks WildFire WF-500 and WF-500-Bto a version that resolves this vulnerability.Fixed in 10.2.18-h6 - Upgrade
Upgrade
Palo Alto Networks WildFire WF-500 and WF-500-Bto a version that resolves this vulnerability.Fixed in 11.1.15 - Upgrade
Upgrade
Palo Alto Networks WildFire WF-500 and WF-500-Bto a version that resolves this vulnerability.Fixed in 11.2.12 - Upgrade
Upgrade
Palo Alto Networks WildFire WF-500 and WF-500-Bto a version that resolves this vulnerability.Fixed in 12.1.7 - Compensating control
With a Threat Prevention subscription, block the vulnerability by enabling Threat ID 510010 (from Applications and Threats content version 9100-10044 and later). Note: this Threat ID requires SSL Decryption.
- Compensating control
For airgapped deployments, restrict access to WildFire 500 appliances (WF-500, WF-500-B) to only trusted internal IP addresses.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0259?
The severity of CVE-2026-0259 is classified as MEDIUM.
What systems are affected by CVE-2026-0259?
CVE-2026-0259 affects Palo Alto Networks WildFire WF-500 and WF-500-B appliances.
How do I fix CVE-2026-0259?
To fix CVE-2026-0259, apply the security patch provided by Palo Alto Networks for the affected WildFire appliances.
What type of vulnerability is CVE-2026-0259?
CVE-2026-0259 is classified as an arbitrary file read and delete vulnerability.
What could be the impact of exploiting CVE-2026-0259?
Exploiting CVE-2026-0259 could allow attackers to read sensitive information and delete files on the affected WildFire appliances.