Critical Manufacturing Gear Exposed by PAN-OS Flaw

This is not just a firewall problem. A PAN-OS captive-portal buffer overflow can give an unauthenticated attacker root code execution on Siemens RUGGEDCOM APE1808 devices, so a perimeter surface becomes a foothold inside critical manufacturing networks. CISA maps CVE-2026-0300 to Siemens RUGGEDCOM APE1808, all versions. Siemens says fixes are still being prepared, and CISA lists mitigations that keep the User-ID Authentication Portal or response pages constrained to trusted internal use. The risk stays live until those controls are in place. An overdue KEV entry and a sharp EPSS rise point to exposed devices that may remain reachable on operational sites even without a vendor patch.

Part of the PlainSec briefing for 2026-05-20

Sources