CyberzSOC

Publication detail
← Back to advisories & guidance

2026-006: Critical Vulnerability in PAN-OS ↗ source

May 6, 2026 CERT-EU Advisory

Summary

This vulnerability allows an unauthenticated attacker to execute arbitrary Palo Alto observed limited exploitation of this vulnerability. It is strongly recommended updating affected appliances as soon as patches will be available, and to apply workarounds and The vulnerability CVE-2026-0300, with the CVSS score of 9.3, is a buffer overflow in the UserID Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software. An unauthenticated attacker could execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. [1] This issue is applicable only to PA-Series and VM-Series firewalls that are configured to use User-ID Authentication Portal. The following PAN-OS versions are affected: Additional information is available in the vendor’s advisory [1]. The patches are not available at the time of writing, but are scheduled to be released in the near future.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2026-0300 9.3 Critical Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can al…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.