Palo Alto Networks disclosed and patched CVE-2026-0300, a critical PAN-OS vulnerability in the User-ID Authentication Portal that can let an unauthenticated remote attacker execute arbitrary code with root privileges. The flaw, rated CVSS 9.3, is described as a stack overflow and out-of-bounds write issue affecting multiple PAN-OS release lines, including versions in the 10.2, 11.1, 11.2, and 12.1 branches, on affected PA Series and VM-Series firewalls.
Palo Alto Networks reported signs of active exploitation, particularly on devices exposed to the internet or reachable from untrusted IP addresses, and CISA added the bug to its Known Exploited Vulnerabilities catalog. Exploitation depends on the Authentication Portal being enabled and a management interface profile with a response page being attached to a Layer 3 interface reachable by untrusted traffic; defenders were urged to upgrade to fixed releases, restrict portal access to trusted zones or IP addresses, disable the feature if unnecessary, and investigate systems for signs of compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CISA later added CVE-2026-0300 to its Known Exploited Vulnerabilities catalog after reports of active exploitation. This elevated the urgency for defenders to patch and investigate affected systems.
Palo Alto Networks said it had observed indications that CVE-2026-0300 was being actively exploited, particularly on exposed devices. The issue affects PA Series and VM-Series firewalls configured as the User-ID Authentication Portal.
Palo Alto Networks disclosed a critical PAN-OS vulnerability, CVE-2026-0300, affecting the USER-ID Authentication Portal and released fixes for affected PAN-OS versions. The flaw can allow an unauthenticated attacker to execute arbitrary code with root privileges.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.