CVE-2026-0300 – Critical Remote Code Execution in Palo Alto Networks PAN-OS Captive Portal
Key takeaways
- Critical buffer overflow (CWE‑787) in the User‑ID Authentication Portal.
- Unauthenticated attacker can gain root on affected PA‑Series and VM‑Series firewalls.
- Actively exploited in the wild; listed in CISA KEV.
- Immediate mitigations: restrict or disable the Authentication Portal; apply vendor patch when released.
- Monitor for suspicious traffic to the portal and deploy the Threat Prevention signature.
Overview
CVE-2026-0300 is a Critical remote code execution flaw in Palo Alto Networks PAN‑OS. The vulnerability resides in the User‑ID™ Authentication Portal (also known as the Captive Portal) service. An unauthenticated attacker can send specially crafted packets to the portal and trigger an out‑of‑bounds write, resulting in root‑level code execution on the firewall.
Technical Details
- Vulnerability type: Buffer overflow (out‑of‑bounds write), classified as CWE‑787.
- Attack vector: Network‑level packet injection against the User‑ID Authentication Portal. No credentials, no user interaction, and no special conditions are required.
- Impact: Arbitrary code execution with full root privileges, enabling complete compromise of the firewall, traffic interception, credential harvesting, and lateral movement.
- Scope: The flaw is present in multiple PAN‑OS releases across the PA‑Series and VM‑Series platforms. Services such as Prisma Access, Cloud NGFW, and Panorama are not affected.
- Exploit evidence: Active exploitation reported by multiple threat feeds since early May 2026; the vulnerability is listed in the CISA KEV catalog.
Severity & Impact
| Metric | Value |
|---|---|
| CVSS | CVSS 9.8 (Critical) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CWE | CWE‑787 |
The combination of network‑only access, no authentication, and root‑level execution makes this one of the most severe firewall vulnerabilities seen in recent years.
Affected Products
The vulnerability affects a wide range of PAN‑OS versions on the following hardware families:
- PA‑Series (e.g., PA‑410, PA‑5000, PA‑7500)
- VM‑Series virtual firewalls
Prisma Access, Cloud NGFW, and Panorama appliances are not impacted. For the complete list of affected models and version ranges, see the live CVE page: https://vulnsocial.com/cve/CVE-2026-0300.
Actionable Insights
- Network segmentation: Ensure the User‑ID Authentication Portal is not exposed to untrusted networks. Place it behind internal VLANs or firewalls.
- Access control: Restrict portal access to trusted IP ranges only. Use ACLs or security policies to block external traffic.
- Disable if unused: If your environment does not require the Authentication Portal, disable it immediately via the UI or CLI.
- Deploy threat signatures: Apply the Palo Alto Threat Prevention signature released on May 5 2026 for PAN‑OS 11.1 and later.
- Log monitoring: Enable detailed logging for portal traffic and watch for anomalous connections or malformed packets.
- Patch readiness: Track vendor patch releases (expected between May 13 and May 28 2026) and plan rapid deployment.
Remediation & Mitigation
- Restrict portal access – configure the Authentication Portal to accept connections only from trusted internal IP addresses.
- Disable the portal – if the feature is not required, turn it off via Device > User Identification > Authentication Portal Settings.
- Apply the official patch as soon as Palo Alto Networks releases it.
- Enable the Threat Prevention signature for affected PAN‑OS versions (available from May 5 2026).
- Monitor logs for any attempt to reach the portal and investigate suspicious sources.
- Validate post‑remediation – confirm that the portal is no longer reachable from the internet and that the patch is correctly applied.
Bottom line
CVE-2026-0300 is a Critical remote code execution vulnerability that gives attackers root on vulnerable Palo Alto Networks firewalls. Immediate mitigation—restricting or disabling the User‑ID Authentication Portal—combined with rapid patch deployment is essential to prevent full network compromise.
References
- Vendor advisory:
https://security.paloaltonetworks.com/CVE-2026-0300 - CISA Known Exploited Vulnerabilities catalog:
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-0300 - Siemens third‑party advisory:
https://cert-portal.siemens.com/productcert/html/ssa-967325.html - Live intelligence and timeline:
https://vulnsocial.com/cve/CVE-2026-0300 - VulnSocial home:
https://vulnsocial.com
#hashtags: #CVE #CVE20260300 #Critical #RCE #CISAKEV #PaloAlto #PANOS
