Skip to main content
Mallory
Back to stories
actively-exploited-vulnerabilityperimeter-device-exposurewidely-deployed-product-advisoryembedded-device-vulnerability

Active Exploitation of PAN-OS Captive Portal Flaw Gives Attackers Root on Firewalls

Updated 6d agoFirst seen May 6, 202628 sources

Palo Alto Networks disclosed CVE-2026-0300, a critical buffer overflow in the PAN-OS User-ID Authentication Portal (also called the Captive Portal) that is being exploited in the wild to achieve unauthenticated remote code execution with root privileges. The flaw is an out-of-bounds write triggered by specially crafted packets and affects exposed PA-Series and VM-Series firewalls running multiple PAN-OS 10.2, 11.1, 11.2, and 12.1 versions. Palo Alto assigned the issue a CVSS 9.3 when the portal is reachable from the public internet or other untrusted networks, and 8.7 when access is limited to trusted internal IP addresses.

The company said observed attacks have focused on Authentication Portal instances exposed to untrusted IP addresses, while Prisma Access, Cloud NGFW, and Panorama are not affected. At disclosure, fixes were not yet broadly available, with patch releases scheduled to begin in mid-May and continue through late May 2026. Palo Alto urged customers to immediately restrict portal access to trusted zones or internal IPs, or disable the Authentication Portal if it is not required, and said a Threat Prevention Signature for PAN-OS 11.1 and later was released as an added mitigation layer.

Share:
Active Exploitation of PAN-OS Captive Portal Flaw Gives Attackers Root on Firewalls
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the earliest known activity through the most recent confirmed update.

6 EVENTS
Apr 9, 20261mo ago

Palo Alto links CVE-2026-0300 exploitation to CL-STA-1132 activity

Palo Alto Networks said suspected state-sponsored cluster CL-STA-1132 began attempting to exploit CVE-2026-0300 on April 9, 2026, and achieved successful remote code execution about a week later by injecting shellcode into an nginx worker process. The company also described post-exploitation behavior including log deletion, Active Directory enumeration, and deployment of EarthWorm and ReverseSocks5 on a second device by April 29.

PAN-OS RCE Exploit Under Active Use Enabling Root Access and Espionage
May 5, 202613d ago

Palo Alto releases Threat Prevention Signature for CVE-2026-0300

Palo Alto Networks released a Threat Prevention Signature for PAN-OS 11.1 and later as a mitigation for CVE-2026-0300. The signature was made available ahead of full software patches to help reduce exploitation risk.

May 6, 202612d ago

Palo Alto discloses CVE-2026-0300 under active exploitation

Palo Alto Networks disclosed CVE-2026-0300, a critical unauthenticated buffer overflow in the PAN-OS User-ID Authentication Portal that can lead to remote code execution with root privileges. The company said the flaw is being exploited in the wild, particularly against internet-exposed or otherwise untrusted portal deployments.

Palo Alto announces patch rollout schedule for affected PAN-OS versions

Alongside the disclosure, Palo Alto said fixes for affected PAN-OS 10.2, 11.1, 11.2, and 12.1 versions would begin rolling out between May 13 and May 28, 2026. Until patches are available, customers were advised to restrict portal access to trusted internal IPs or disable the Authentication Portal if unused.

CISA adds CVE-2026-0300 to Known Exploited Vulnerabilities catalog

CISA added Palo Alto Networks PAN-OS CVE-2026-0300 to its Known Exploited Vulnerabilities Catalog, formally recognizing the flaw as exploited in the wild. The agency directed organizations to apply vendor mitigations, follow BOD 22-01 guidance for cloud services, or discontinue use if mitigations were unavailable.

Add Updated KEV Files for 2026-05-06 · cisagov/kev-data@7075827 · GitHub

CISA sets May 9 remediation deadline for CVE-2026-0300

After adding CVE-2026-0300 to the KEV catalog, CISA required Federal Civilian Executive Branch agencies to remediate the actively exploited Palo Alto PAN-OS flaw by May 9, 2026, under Binding Operational Directive 22-01. The agency urged immediate mitigations because vendor patches were still pending.

CISA Warns of Palo Alto PAN-OS Vulnerability Exploited to Gain Root Access
SOURCE COVERAGE

Sources

28 references tracked. Mallory keeps watching after this page renders.

28 SOURCESView all
Secpod BlogNews
May 11, 2026

CL-STA-1132 Weaponizes PAN-OS RCE for Silent Root-Level Takeovers - SecPod Blog

secpod.com

Open source
Belgium Ccb Security AdvisoriesNews
May 11, 2026

Warning: Critical Remote Code Execution vulnerability in Palo Alto PAN-OS User-ID Authentication Portal, Apply patches as soon as available! | CCB Belgium

ccb.belgium.be

Open source
Security AffairsNews
May 7, 2026

Nation-state actors exploit Palo Alto PAN-OS zero-day for weeks

securityaffairs.com

Open source
ScworldNews
May 7, 2026

Palo Alto Networks says patch for exploited PAN-OS firewall bug forthcoming | news | SC Media

scworld.com

Open source
Cyber Security NewsNews
May 7, 2026

CISA Warns of Palo Alto PAN-OS Vulnerability Exploited to Gain Root Access

cybersecuritynews.com

Open source
The Hacker NewsNews
May 7, 2026

PAN-OS RCE Exploit Under Active Use Enabling Root Access and Espionage

thehackernews.com

Open source
Security AffairsNews
May 7, 2026

U.S. CISA adds a flaw in Palo Alto Networks PAN-OS to its Known Exploited Vulnerabilities catalog

securityaffairs.com

Open source
Help Net SecurityNews
May 7, 2026

State-sponsored hackers likely behind zero-day attacks on Palo Alto firewalls - Help Net Security

helpnetsecurity.com

Open source
Cso OnlineNews
May 7, 2026

Critical Palo Alto Networks software bug hits exposed firewalls | CSO Online

csoonline.com

Open source
CyberscoopNews
May 6, 2026

A critical Palo Alto PAN-OS zero-day is being exploited in the wild | CyberScoop

cyberscoop.com

Open source
ScworldNews
May 6, 2026

Palo Alto Networks warns of critical PAN-OS vulnerability exploited in the wild | brief | SC Media

scworld.com

Open source
Ca CcsNews
May 6, 2026

Palo Alto Networks security advisory (AV26-425) - Canadian Centre for Cyber Security

cyber.gc.ca

Open source
Socprime BlogNews
May 6, 2026

CVE-2026-0300: PAN-OS Zero-Day Exposes Firewalls

socprime.com

Open source
Socprime BlogNews
May 6, 2026

CVE-2026-0300: PAN-OS Zero-Day Exposes Firewalls

socprime.com

Open source
Thecyberexpress Com VulnerabilitiesNews
May 6, 2026

CVE-2026-0300 Buffer Overflow Vulnerability In PAN-OS

thecyberexpress.com

Open source
Security AffairsNews
May 6, 2026

Palo Alto Networks PAN-OS flaw exploited for remote code execution

securityaffairs.com

Open source
The Hacker NewsNews
May 6, 2026

Palo Alto PAN-OS Flaw Under Active Exploitation Enables Remote Code Execution

thehackernews.com

Open source
Cyber Security NewsNews
May 6, 2026

Critical Palo Alto Firewalls Vulnerability Exploited in the Wild to Gain Root Access

cybersecuritynews.com

Open source
Nuclei Templates Pull RequestsNews
May 6, 2026

Add CVE-2026-0300 PAN-OS Captive Portal detection template by rxerium · Pull Request #16121 · projectdiscovery/nuclei-templates · GitHub

github.com

Open source
Cert Eu Security AdvisoriesAdvisories
May 6, 2026

CERT-EU - Critical Vulnerability in PAN-OS

cert.europa.eu

Open source
Rapid7 BlogNews
May 6, 2026

Critical Buffer Overflow in Palo Alto Networks PAN-OS User-ID Authentication Portal (CVE-2026-0300)

rapid7.com

Open source
Cisa Kev Data CommitsAdvisories
May 6, 2026

Add Updated KEV Files for 2026-05-06 · cisagov/kev-data@7075827 · GitHub

github.com

Open source
Bank Info SecurityNews
May 6, 2026

Palo Alto Firewalls Being Exploited; No Patch Yet Available

bankinfosecurity.com

Open source
Cisa AdvisoriesAdvisories
May 6, 2026

CISA Adds One Known Exploited Vulnerability to Catalog | CISA

cisa.gov

Open source
Cvefeed High SeverityAdvisories
May 6, 2026

CVE-2026-0300 - PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal

cvefeed.io

Open source
DarkwebinformerNews
May 6, 2026

Palo Alto Networks Warns of Actively Exploited PAN-OS Zero-Day Granting Root Access

darkwebinformer.com

Open source
CyberthroneNews
May 6, 2026

CVE-2026-0300 - Critical PAN-OS Buffer Overflow Bug - TheCyberThrone

thecyberthrone.in

Open source
Help Net SecurityNews
May 6, 2026

Root-level RCE vulnerability in Palo Alto firewalls exploited (CVE-2026-0300) - Help Net Security

helpnetsecurity.com

Open source
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.