Palo Alto CVE-2026-0300 Actively Exploited
PAN released an advisory about the vulnerability on Tuesday and said it will release a patch in an upcoming version of PAN-OS.

PAN released an advisory about the vulnerability on Tuesday and said it will release a patch in an upcoming version of PAN-OS.
May 7, 2026 | 1 min read

Palo Alto Networks is warning customers that attackers are exploiting a critical buffer overflow in the User-ID Authentication Portal in many of its products that can be exploited pre-authentication and for which there is no fix available yet.
PAN released an advisory about the vulnerability on Tuesday and said it will release a patch in an upcoming version of PAN-OS, with various affected versions getting updates on either May 13 or May 28. The bug (CVE-2026-0300) affects versions 12.1, 11.2, 11.1, and 10.2 of PAN-OS and is present only when PA-Series and VM-Series firewalls have the User-ID Authentication Portal enabled.
“A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets,” the advisory says.
“Limited exploitation has been observed targeting Palo Alto Networks User-ID Authentication Portals that are exposed to untrusted IP addresses and/or the public internet. Customers following standard security best practices, such as restricting sensitive portals to trusted internal networks are at a greatly reduced risk.”
Security researchers and incident response teams have been working on the issue since the exploitation began, but there’s no further details on exploitation attribution or volume,
In lieu of a patch, PAN recommends that customers running affected versions of PAN-OS take the following steps to mitigate the risk of the vulnerability: restrict access to the portal only to trusted zones, or disable the portal if it’s not needed.
CISA has added this vulnerability to its Known Exploited Vulnerability catalog, too.
May 7, 2026 | 1 min read
Dennis Fisher is an award-winning journalist and author. He is one of the co-founders of Decipher and Threatpost and has been writing about cybersecurity since 2000. Dennis enjoys finding the stories behind the headlines and digging into the motivations and thinking of both defenders and attackers. He is the author of 2.5 novels and once met Shaq. Contact: dennis at decipher.sc.