Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3511 articles · 182385 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-0300EXPLOITEDPATCHED
palo alto networks · pan-os

PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal

Description

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.

Affected Products

VendorProductVersions
palo alto networkspan-os12.1.0, 11.2.0, 11.1.0, 10.2.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
palo alto networkspa-1410cve_cpe95%
palo alto networkspa-1420cve_cpe95%
palo alto networkspa-3410cve_cpe95%
palo alto networkspa-3420cve_cpe95%
palo alto networkspa-3430cve_cpe95%

References

  • https://security.paloaltonetworks.com/CVE-2026-0300(vendor-advisory)

Related News (20 articles)

Tier C
Palo Alto Unit 422h ago
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
→ No new info (linked only)
Tier E
Hacker News57d ago
AI Vulnerability Intelligence Agent Converts CVEs to Actionable Security Reports
→ No new info (linked only)
Tier D
The Hacker News76d ago
ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ Stories
→ No new info (linked only)
Tier D
The Hacker News79d ago
⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and More
→ No new info (linked only)
Tier B
CERT-FR80d ago
Bulletin d'actualité CERTFR-2026-ACT-021 (11 mai 2026)
→ No new info (linked only)
Tier D
CSO Online83d ago
Palo Alto Networks firewall flaw has been exploited for several weeks
→ No new info (linked only)
Tier E
Hacker News83d ago
State-backed hackers hammer Palo Alto firewall zero-day before patch lands
→ No new info (linked only)
Tier D
The Hacker News83d ago
PAN-OS RCE Exploit Under Active Use Enabling Root Access and Espionage
→ No new info (linked only)
Tier D
CSO Online84d ago
Critical Palo Alto Networks software bug hits exposed firewalls
→ No new info (linked only)
Tier C
Palo Alto Unit 4284d ago
Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution
→ No new info (linked only)
Tier C
VulDB84d ago
CVE-2026-0300 | Palo Alto Cloud NGFW/PAN-OS/Prisma Access out-of-bounds write
→ No new info (linked only)
Tier B
CCCS Canada84d ago
Palo Alto Networks security advisory (AV26-425)
→ No new info (linked only)
Tier C
Rapid7 Blog84d ago
Critical Buffer Overflow in Palo Alto Networks PAN-OS User-ID Authentication Portal (CVE-2026-0300)
→ No new info (linked only)
Tier B
BSI Advisories85d ago
[NEU] [kritisch] Palo Alto Networks PAN-OS: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Administratorrechten
→ No new info (linked only)
Tier D
Help Net Security85d ago
Root-level RCE vulnerability in Palo Alto firewalls exploited (CVE-2026-0300)
→ No new info (linked only)
Tier D
BleepingComputer85d ago
Palo Alto Networks warns of firewall RCE zero-day exploited in attacks
→ No new info (linked only)
Tier D
Heise Security85d ago
PAN-OS-Lücke wird angegriffen, Updates erst in Wochen geplant
→ No new info (linked only)
Tier D
The Hacker News85d ago
Palo Alto PAN-OS Flaw Under Active Exploitation Enables Remote Code Execution
→ No new info (linked only)
Tier D
SecurityWeek85d ago
Palo Alto Networks to Patch Zero-Day Exploited to Hack Firewalls
→ No new info (linked only)
Tier B
CERT-FR85d ago
Vulnérabilité dans Palo Alto Networks User-ID Authentication Portal (06 mai 2026)
→ No new info (linked only)
CVSS 3.17.5 NONE
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
All12.1.712.1.4-h511.2.1211.2.10-h611.2.7-h1311.2.4-h1711.1.1511.1.13-h511.1.10-h2511.1.7-h611.1.6-h3211.1.4-h3310.2.18-h610.2.16-h710.2.13-h2110.2.10-h3610.2.7-h34
CWECWE-787
PublishedMay 6, 2026
Last enriched76d agov6
Tags
zero-dayremote code executioncriticalespionage
Trending Score111🔥
Source articles20
Independent13
Info Completeness12/14
Missing: epss, kev

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-0257EXP
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
Trending: 41
NONECVE-2026-0265
PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled
Trending: 18
NONECVE-2026-0288
PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent
Trending: 17
CRITICALCVE-2026-0284EXP
PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)
Trending: 3
HIGHCVE-2026-0286EXP
PAN-OS: Authenticated Command Injection in CLI
Trending: 3

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 6, 2026
Discovered by ZDM
May 6, 2026
Updated: description, severity, activelyExploited
May 6, 2026
Updated: description, severity, cvssEstimate, cweIds, exploitAvailable, iocs, mitreAttack, tags
May 7, 2026
Updated: cweIds, tags
May 7, 2026
Updated: description, cweIds
May 8, 2026
Updated: description
May 14, 2026
Actively Exploited
Jul 14, 2026
Exploit Available
Jul 14, 2026
Patch Available
Jul 14, 2026

Version History

v6
Last enriched 76d ago
v6Tier D76d ago

Updated description with new technical details, changed severity to CRITICAL, and added new IoCs EarthWorm and ReverseSocks5.

description
via The Hacker News
v5Tier D83d ago

Updated description with details about exploitation, added CVE-2026-0300, changed severity to CRITICAL, updated patch availability to May 13, and added 'zero-day' tag.

descriptioncweIds
via CSO Online
v4Tier D83d ago

Updated severity to HIGH, CVSS score to 9.3, added new CWE, and included new tags related to critical and espionage.

cweIdstags
via The Hacker News
v3Tier C84d ago

Updated description with technical details, changed vendor and product names, updated severity to HIGH, added CVSS estimate of 7.5, included new CWE IDs, confirmed exploit availability, and added IOC and MITRE ATT&CK information.

descriptionseveritycvssEstimatecweIdsexploitAvailableiocsmitreAttacktags
via Palo Alto Unit 42
v2Tier C84d ago

Updated description with critical vulnerability details, changed severity to CRITICAL, and noted that there is no exploit available.

descriptionseverityactivelyExploited
via VulDB
v184d ago

Initial creation