ZeroHour
The Recordpublished ()ingested

Palo Alto warns of critical software bug used in firewall attacks

criticalVulnerabilityimportance 60CVE-2026-0300

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-0300
Unauthenticated Out-of-bounds Write RCE in Palo Alto Networks PAN-OS

Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability (CWE-787) in the User-ID Authentication Portal, also known as the Captive Portal service. An unauthenticated attacker can trigger the flaw by sending specially crafted packets to the portal, without needing valid credentials. Successful exploitation allows the attacker to execute arbitrary code with root privileges on the firewall, giving full control of PA-Series and VM-Series devices. Any organization running PA-Series or VM-Series firewalls with the User-ID Authentication Portal service enabled is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-05-06, indicating exploitation in the wild; EPSS puts the 30-day exploitation probability at 31.7% (98th percentile), patches were released on 2026-05-13, no public PoC is known, and CVSS scoring is not yet available.

Do: Apply the PAN-OS patches Palo Alto Networks released on 5/13/2026, prioritizing internet-facing PA-Series and VM-Series firewalls. As an interim mitigation, restrict User-ID Authentication Portal access to trusted zones only, or disable the service entirely if it is not required. Inventory your deployments for use of the Captive Portal/User-ID Authentication Portal and follow CISA KEV and BOD 22-01 requirements, including for affected cloud service instances; note that federal agencies face KEV remediation deadlines.

9.332% KEV
  • Palo Alto Networks PAN-OS
large≈100,000+ PAN-OS firewall deployments; the vulnerable subset (installs with the User-ID Authentication Portal enabled) is likely in the tens of thousands,…
Full article439 words · extracted from therecord.media · click to collapse

Updated 5/8 with additional information from Palo Alto Networks.

Hackers are exploiting a new vulnerability in software from Palo Alto Networks, the company said in an advisory on Wednesday. 

The bug is tracked as CVE-2026-0300 and carries a severity score of 9.3 out of 10, indicating a critical issue. A patch has not been published yet and Palo Alto Networks said it will be included in releases over the next two weeks.

The vulnerability affects the PAN-OS software and the PA-Series and VM-Series firewalls that have certain settings configured. PAN-OS is a popular firewall operating system used by many Fortune 500 companies. 

The Cybersecurity and Infrastructure Security Agency (CISA) confirmed it is being exploited on Wednesday and ordered all U.S. agencies to apply Palo Alto Networks’ mitigations by Saturday. Incident response firm Rapid7 said a patch is likely to be released for many versions by May 13. 

On Thursday, the company said the bug is being exploited by an unnamed state-sponsored group. The threat actors exploiting the bug used open source tools rather than malware to move through victim networks “over a multi-week period,” the company explained.

The activity “remained below the behavioral thresholds of most automated alerting systems” and relied on stolen credentials to reduce its footprint. Palo Alto Networks said it shared its findings with members of the Cyber Threat Alliance. 

“Consequently, this campaign demonstrates that operational restraint — specifically the use of non-persistent access windows — is a primary factor in maintaining long-term residency on edge infrastructure,” the company said.

Cybersecurity experts began warning of CVE-2026-0300 on Tuesday evening, with several companies reporting exploitation following the release of exploit code. 

Palo Alto Networks said the exploitation was focused on authentication portals that are exposed to untrusted IP addresses or the public internet.

“Customers following standard security best practices, such as restricting sensitive portals to trusted internal networks are at a greatly reduced risk,” the company said. 

Due to the popularity of Palo Alto Networks firewalls, vulnerabilities in the company’s products have become prized tools for cybercriminals and nation state attackers. 

Multiple bugs in 2024 affecting lines of Palo Alto Networks firewalls were exploited by cybercriminals and nation-state actors. Palo Alto was previously affected by a vulnerability affecting its firewall product in 2022 that was used in a distributed denial-of-service (DDoS) attack.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/palo-alto-warns-of-critical-software-bug-firewalls