đ° Full Story
Palo Alto Networks disclosed a critical buffer overflow zero-day in its PAN-OS User-ID Authentication Portal (Captive Portal), tracked as CVE-2026-0300, that allows unauthenticated remote code execution with root privileges on PA-Series and VM-Series firewalls.
The company warned of "limited exploitation" and attributed activity to a likely state-sponsored cluster tracked as CL-STA-1132.
Evidence shows unsuccessful attempts from April 9 and successful exploitation and follow-on activity in April, including AD enumeration, use of tunneling tools (EarthWorm, ReverseSocks5), credential collection and log deletion.
Affected PAN-OS branches include versions in the 10.x, 11.x and 12.1 lines when the portal is exposed to untrusted networks.
Palo Alto plans staged software fixes beginning May 13, 2026, with further patches on May 28.
The U.S. CISA added CVE-2026-0300 to its Known Exploited Vulnerabilities catalog, directing federal agencies to apply mitigations.
Until patches are issued, Palo Alto and researchers advise restricting or disabling the User-ID Authentication Portal, disabling response pages on L3 interfaces, and enabling available threat signatures for detection.
đ Based On
đ°ď¸ The Story So Far: An Evolving Timeline
Monday, May 11, 2026 17:36 UTC
Google halts AI-developed zero-day mass exploit
Sunday, May 10, 2026 13:49 UTC
Palo Alto PAN-OS critical zero-day exploited








đŹ Commentary