Palo Alto Networks disclosed CVE-2026-0300, a critical CWE-787 out-of-bounds write in the PAN-OS User-ID Authentication Portal, also known as the Captive Portal, that allows an unauthenticated attacker to achieve remote code execution as root on affected PA-Series and VM-Series firewalls. The flaw was reported as actively exploited in the wild and added to CISA's Known Exploited Vulnerabilities catalog, with exploitation observed against portals reachable from untrusted networks or the public internet. Palo Alto said Prisma Access, Cloud NGFW, and Panorama are not affected, while vulnerable PAN-OS branches included 10.2, 11.1, 11.2, and 12.1 below fixed releases.
Reporting on observed intrusions said attackers used the firewall access for shellcode injection into nginx worker processes, credential extraction, Active Directory enumeration, outbound tunneling with tools such as EarthWorm and ReverseSocks5, internal pivoting, and anti-forensic log cleanup. Palo Alto began releasing patches in staged waves and urged defenders to disable the Captive Portal if unused or restrict it to trusted IPs and zones, enable available threat-prevention signatures, and treat previously exposed devices as potentially fully compromised by auditing configurations, checking admin accounts and SSH keys, rotating credentials, and monitoring for persistence or suspicious outbound connections.
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks began releasing patches for CVE-2026-0300 in staged waves starting on May 13, 2026, for affected PAN-OS branches. The company continued to recommend restricting Authentication Portal access to trusted zones or disabling the feature until systems were fully remediated.
At disclosure, Palo Alto said fixes were not yet available but published estimated release dates for patched PAN-OS versions. Reporting said the first wave of patches would begin on May 13, 2026, followed by a second wave on May 28, 2026.
On May 6, 2026, CISA added CVE-2026-0300 to its Known Exploited Vulnerabilities catalog due to active exploitation. The listing set a remediation deadline of May 9, 2026 for affected federal agencies.
On May 6, 2026, Palo Alto Networks disclosed CVE-2026-0300 as a critical unauthenticated out-of-bounds write / buffer overflow in the PAN-OS User-ID Authentication Portal that can lead to root-level remote code execution on affected PA-Series and VM-Series firewalls. The vendor said the flaw was being actively exploited in the wild and advised restricting or disabling the Captive Portal where possible.
By April 16, 2026, attackers had achieved remote code execution as root via CVE-2026-0300. Reported follow-on activity included shellcode injection into nginx worker processes, credential extraction, Active Directory enumeration, anti-forensic log cleanup, and outbound tunneling with tools such as EarthWorm and ReverseSocks5.
Palo Alto Networks and Unit 42 observed limited in-the-wild exploitation of CVE-2026-0300 starting on April 9, 2026, targeting PAN-OS User-ID Authentication Portals exposed to untrusted networks or the public internet.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
codeby.net
Open sourcecodeby.net
Open sourcecodeby.net
Open sourcecensys.com
Open sourcetechnadu.com
Open sourcetenable.com
Open sourcelabs.beazley.security
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.