Palo Alto Networks is warning customers that attackers are exploiting a critical buffer overflow in the User-ID Authentication Portal in many of its products that can be exploited pre-authentication and for which there is no fix available yet. 

PAN released an advisory about the vulnerability on Tuesday and said it will release a patch in an upcoming version of PAN-OS, with various affected versions getting updates on either May 13 or May 28. The bug (CVE-2026-0300) affects versions 12.1, 11.2, 11.1, and 10.2 of PAN-OS and is present only when PA-Series and VM-Series firewalls have the User-ID Authentication Portal enabled.

“A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets,” the advisory says.

“Limited exploitation has been observed targeting Palo Alto Networks User-ID Authentication Portals that are exposed to untrusted IP addresses and/or the public internet. Customers following standard security best practices, such as restricting sensitive portals to trusted internal networks are at a greatly reduced risk.” 

Security researchers and incident response teams have been working on the issue since the exploitation began, but there’s no further details on exploitation attribution or volume, 

In lieu of a patch, PAN recommends that customers running affected versions of PAN-OS take the following steps to mitigate the risk of the vulnerability: restrict access to the portal only to trusted zones, or disable the portal if it’s not needed. 

CISA has added this vulnerability to its Known Exploited Vulnerability catalog, too.