Palo Alto Networks disclosed CVE-2026-0300, a critical CWE-787 buffer overflow in the PAN-OS User-ID Authentication Portal (Captive Portal) that allows unauthenticated remote code execution as root on affected PA-Series and VM-Series firewalls. The flaw carries a CVSS v4 score of 9.3 when the portal is exposed to untrusted networks or the public internet, and Palo Alto confirmed limited in-the-wild exploitation against exposed portals. Affected versions span PAN-OS 10.2, 11.1, 11.2, and 12.1, while Prisma Access, Cloud NGFW, and Panorama are not affected. With patches not immediately available at disclosure, Palo Alto said fixed releases would begin rolling out between May 13 and May 28 and urged customers to restrict portal access to trusted internal zones or disable the feature entirely; the company also released a Threat Prevention Signature for PAN-OS 11.1 and later.
U.S. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and ordered federal civilian agencies to remediate by the mandated deadline, while other national and regional cyber authorities issued parallel alerts. Palo Alto Unit 42 and multiple reports linked the activity to a likely state-sponsored cluster tracked as CL-STA-1132, which reportedly probed targets for weeks, injected shellcode into an nginx worker process, deleted crash artifacts and logs, enumerated Active Directory through firewall-linked service accounts, and used EarthWorm and ReverseSocks5 tunnels for command and control and lateral movement. Researchers warned that thousands of internet-exposed PAN-OS instances remain reachable, making perimeter firewalls with exposed Captive Portal services high-priority compromise candidates.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
About a week after initial probing, the threat cluster successfully exploited CVE-2026-0300 to gain remote code execution and inject shellcode into an nginx worker process on a targeted firewall.
Palo Alto Networks said a likely state-sponsored activity cluster tracked as CL-STA-1132 was behind exploitation of CVE-2026-0300. The company described shellcode injection into nginx worker processes, log deletion, Active Directory enumeration, and use of EarthWorm and ReverseSocks5 tunnels.
CISA added CVE-2026-0300 to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. Federal Civilian Executive Branch agencies were given a remediation deadline of May 9, 2026 under BOD 22-01.
Palo Alto Networks disclosed CVE-2026-0300 as a critical PAN-OS User-ID Authentication Portal vulnerability that allows unauthenticated remote code execution with root privileges on exposed PA-Series and VM-Series firewalls. The company said exploitation had been observed in limited attacks and that patches would begin rolling out starting May 13, 2026.
Palo Alto Networks published a security advisory for CVE-2026-0300, a critical unauthenticated buffer overflow in the PAN-OS User-ID Authentication Portal affecting multiple PAN-OS branches. The advisory said the flaw was being actively exploited and recommended restricting or disabling the portal until fixes were available.
Palo Alto Networks released a Threat Prevention Signature for PAN-OS 11.1 and later as an interim mitigation against exploitation of CVE-2026-0300.
On April 29, 2026, attackers triggered a SAML flood to force high-availability failover, then re-exploited CVE-2026-0300 on a secondary firewall. They deployed EarthWorm and ReverseSocks5 tunneling tools on the second device.
Palo Alto Networks said CL-STA-1132 attempted exploitation of CVE-2026-0300 as early as April 9, 2026, marking the start of the observed campaign against exposed PAN-OS devices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
26 references tracked. Mallory keeps watching after this page renders.
secpod.com
Open sourceccb.belgium.be
Open sourcesecurityaffairs.com
Open sourcescworld.com
Open sourcedarkwebinformer.com
Open sourcerapid7.com
Open sourcehelpnetsecurity.com
Open sourcecert.europa.eu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.