CVE-2020-2040Active Exploitation(paloaltonetworks / pan-os)

LOWCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for paloaltonetworks pan-os systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A buffer overflow vulnerability in PAN-OS allows an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with root privileges by sending a malicious request to the Captive Portal or Multi-Factor Authentication interface. This issue impacts: All versions of PAN-OS 8.0; PAN-OS 8.1 versions earlier than PAN-OS 8.1.15; PAN-OS 9.0 versions earlier than PAN-OS 9.0.9; PAN-OS 9.1 versions earlier than PAN-OS 9.1.3.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-120

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pan-os

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
pan-os

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-06: 1Active Exploitation · 2026-05-06: 1Technical Details · 2026-05-06: 105-06
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
Full discourse1 post
  • VulnTracker@vuln_tracker
    Active Exploitation

    The detail most teams will miss in their patch planning: this is the second critical unauth root RCE in the same Captive Portal component in six years (CVE-2020-2040 was the first). Same product, same component, same bug class. The pattern matters more than the individual CVE. Wrote up what to actually do today and the longer perimeter pattern: https://vulntracker.io/blog/palo-alto-pan-os-cve-2026-0300-unauth-rce-active-exploitation/

    Post summary

    CVE‑2026‑0300, a second critical unauthenticated root RCE in Palo Alto’s Captive Portal component, is reportedly actively exploited in the wild, and a linked blog post outlines mitigation steps.

    00000181
    619 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSpaloaltonetworkspan-os---

Explore more