📰 Full Story
Palo Alto Networks on May 6–8, 2026 warned of a critical zero-day (CVE-2026-0300) in PAN‑OS that is being actively exploited in the wild.
The buffer‑overflow flaw resides in the User‑ID Authentication (Captive) Portal and can allow unauthenticated attackers to achieve remote code execution with root privileges on PA‑Series and VM‑Series firewalls.
Palo Alto said exploitation has been limited but observed for several weeks, with Unit 42 tracking activity as cluster CL‑STA‑1132 and evidence of post‑exploit actions including log deletion, Active Directory enumeration and deployment of tunneling tools (EarthWorm, ReverseSocks5). CVSS was reported at 9.3 for internet‑exposed deployments.
Prisma Access, Cloud NGFW and Panorama appliances are not affected.
CISA added the bug to its Known Exploited Vulnerabilities catalog and vendors reported varying exposure counts (Shadowserver ~5,800 exposed VM instances; Wiz/Rapid7 reported other exposure metrics). Palo Alto advised immediate mitigations — restrict or disable the Authentication Portal, disable Response Pages on internet‑facing interfaces and apply threat prevention signatures — and said software fixes will begin rolling out from May 13, 2026, with further builds later in May.







💬 Commentary