ZeroHour
CERT-EU Advisoriespublished ()ingested

2026-006: Critical Vulnerability in PAN-OS

highVulnerability exploited in the wildimportance 66CVE-2026-0300
AI summary · glm-5.3-flash

Palo Alto Networks PAN-OS User-ID Authentication Portal flaw allows unauthenticated root RCE; limited exploitation observed and patches still pending.

Palo Alto Networks disclosed CVE-2026-0300 (CVSS 9.3), a buffer overflow in the PAN-OS User-ID Authentication Portal (Captive Portal) that enables unauthenticated arbitrary code execution with root privileges on PA-Series and VM-Series firewalls. Only appliances configured to use the Authentication Portal are affected. Palo Alto observed limited exploitation; at publication patches were not yet available, so restricting portal access to trusted zones or disabling it was recommended as mitigation.

  • Unauthenticated root RCE via crafted packets to the Captive Portal
  • Only PA-Series and VM-Series firewalls with User-ID Authentication Portal affected
  • Palo Alto observed limited exploitation of the flaw
  • Mitigate by restricting portal access to trusted zones or disabling it

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-0300
Unauthenticated Out-of-bounds Write RCE in Palo Alto Networks PAN-OS

Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability (CWE-787) in the User-ID Authentication Portal, also known as the Captive Portal service. An unauthenticated attacker can trigger the flaw by sending specially crafted packets to the portal, without needing valid credentials. Successful exploitation allows the attacker to execute arbitrary code with root privileges on the firewall, giving full control of PA-Series and VM-Series devices. Any organization running PA-Series or VM-Series firewalls with the User-ID Authentication Portal service enabled is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-05-06, indicating exploitation in the wild; EPSS puts the 30-day exploitation probability at 31.7% (98th percentile), patches were released on 2026-05-13, no public PoC is known, and CVSS scoring is not yet available.

Do: Apply the PAN-OS patches Palo Alto Networks released on 5/13/2026, prioritizing internet-facing PA-Series and VM-Series firewalls. As an interim mitigation, restrict User-ID Authentication Portal access to trusted zones only, or disable the service entirely if it is not required. Inventory your deployments for use of the Captive Portal/User-ID Authentication Portal and follow CISA KEV and BOD 22-01 requirements, including for affected cloud service instances; note that federal agencies face KEV remediation deadlines.

9.332% KEV
  • Palo Alto Networks PAN-OS
large≈100,000+ PAN-OS firewall deployments; the vulnerable subset (installs with the User-ID Authentication Portal enabled) is likely in the tens of thousands,…
Full article303 words · extracted from cert.europa.eu · click to collapse

Release Date: 06-05-2026 08:44:32

History:

  • 06/05/2026 --- v1.0 -- Initial publication

Summary

On 6 May 2026, Palo Alto published a security advisory addressing a critical vulnerability affecting PAN-OS [1]. This vulnerability allows an unauthenticated attacker to execute arbitrary code with root privileges.

Palo Alto observed limited exploitation of this vulnerability. It is strongly recommended updating affected appliances as soon as patches will be available, and to apply workarounds and mitigation in the meantime.

Technical Details

The vulnerability CVE-2026-0300, with the CVSS score of 9.3, is a buffer overflow in the User-ID Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software. [1]

An unauthenticated attacker could execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. [1]

Affected Products

This issue is applicable only to PA-Series and VM-Series firewalls that are configured to use User-ID Authentication Portal.

The following PAN-OS versions are affected:

  • Versions prior to 12.1.4-h5
  • Versions prior to 12.1.7
  • Versions prior to 11.2.4-h17
  • Versions prior to 11.2.7-h13
  • Versions prior to 11.2.10-h6
  • Versions prior to 11.2.12
  • Versions prior to 11.1.4-h33
  • Versions prior to 11.1.6-h32
  • Versions prior to 11.1.7-h6
  • Versions prior to 11.1.10-h25
  • Versions prior to 11.1.13-h5
  • Versions prior to 11.1.15
  • Versions prior to 10.2.7-h34
  • Versions prior to 10.2.10-h36
  • Versions prior to 10.2.13-h21
  • Versions prior to 10.2.16-h7
  • Versions prior to 10.2.18-h6

Additional information is available in the vendor’s advisory [1].

Recommendations

The patches are not available at the time of writing, but are scheduled to be released in the near future. It is recommended updating affected devices as soon as the patches will be released.

Mitigation

It is possible to mitigate the risk of this flaw by taking either of the following actions [1]:

  • Restrict User-ID Authentication Portal access to only trusted zones.
  • Disable User-ID Authentication Portal if not required.

References

[1] https://security.paloaltonetworks.com/CVE-2026-0300

Text extracted automatically; images, tables and formatting may be missing. Original: https://cert.europa.eu/publications/security-advisories/2026-006/