Vulnerabilities & Exploits

Critical Manufacturing Gear Exposed by PAN-OS Flaw

This is not just a firewall problem. A PAN-OS captive-portal buffer overflow can give an unauthenticated attacker root code execution on Siemens RUGGEDCOM APE1808 devices, so a perimeter surface becomes a foothold inside critical manufacturing networks.

CISA maps CVE-2026-0300 to Siemens RUGGEDCOM APE1808, all versions. Siemens says fixes are still being prepared, and CISA lists mitigations that keep the User-ID Authentication Portal or response pages constrained to trusted internal use.

The risk stays live until those controls are in place. An overdue KEV entry and a sharp EPSS rise point to exposed devices that may remain reachable on operational sites even without a vendor patch.

1 source · May 19

CVE-2026-0300

NVD KEV

Known exploited · CISA KEV

EPSS 32% (98th percentile).

CISA federal remediation date May 9 · date passed

Timeline

Sources

Vendor digest: Palo Alto Networks

Part of the PlainSec briefing for 2026-05-19

Every edition of this story: Critical Manufacturing Gear Exposed by PAN-OS Flaw

More from today