VORANT. Threat Intelligence Sign in Get the full feed

Siemens RUGGEDCOM Hit by PAN-OS Flaws

medium vulnerability manufacturing

Siemens RUGGEDCOM APE1808 devices running Palo Alto Networks Virtual NGFW inherit three PAN-OS vulnerabilities allowing XSS and root-level command execution by authenticated admins.

CISA republished a Siemens ProductCERT advisory (SSA-104023) detailing three vulnerabilities in Palo Alto Networks PAN-OS software that affect Siemens RUGGEDCOM APE1808 devices bundled with Palo Alto Networks Virtual NGFW. These industrial edge devices are deployed worldwide in the Critical Manufacturing sector, with Siemens headquartered in Germany.

The vulnerabilities include a stored cross-site scripting flaw (CVE-2026-0266) that lets a malicious authenticated administrator inject JavaScript via the web interface, and two privilege-escalation/command-injection issues (CVE-2026-0272 and CVE-2026-0273) that allow an authenticated CLI or Web UI administrator to execute arbitrary commands with root privileges. All three require existing authenticated administrative access, which Palo Alto Networks notes significantly reduces exploitability when management interfaces are restricted to trusted internal IPs and CLI access is limited to a small admin group.

No public exploitation has been reported. Remediation requires contacting Siemens customer support for patch information, and CISA recommends standard ICS network segmentation practices such as isolating control system networks from business networks and avoiding direct internet exposure of management interfaces.

Mentioned in this report

Vulnerabilities CVE-2026-0266CVE-2026-0272CVE-2026-0273

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-02

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free