← Back to advisories & guidance
May 6, 2026
CERT-EU
Advisory
Summary
This vulnerability allows an unauthenticated attacker to execute arbitrary Palo Alto observed limited exploitation of this vulnerability. It is strongly recommended updating affected appliances as soon as patches will be available, and to apply workarounds and The vulnerability CVE-2026-0300, with the CVSS score of 9.3, is a buffer overflow in the UserID Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software. An unauthenticated attacker could execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. [1] This issue is applicable only to PA-Series and VM-Series firewalls that are configured to use User-ID Authentication Portal. The following PAN-OS versions are affected: Additional information is available in the vendor’s advisory [1]. The patches are not available at the time of writing, but are scheduled to be released in the near future.
News Coverage
No coverage found in monitored research blogs or news feeds.
CVEs Referenced in This Publication
Extracted from the publication text. Each CVE links to its tracked detail page.
Vendors Named in This Publication
Each vendor links to its Known Exploited Vulnerabilities catalog page.
Only vendors that appear in the KEV catalog are listed, either because
the publication cites one of their KEV entries or because it names them
directly.