
The detail most teams will miss in their patch planning: this is the second critical unauth root RCE in the same Captive Portal component in six years (CVE-2020-2040 was the first). Same product, same component, same bug class. The pattern matters more than the individual CVE. Wrote up what to actually do today and the longer perimeter pattern: https://vulntracker.io/blog/palo-alto-pan-os-cve-2026-0300-unauth-rce-active-exploitation/
Post summary
CVE‑2026‑0300, a second critical unauthenticated root RCE in Palo Alto’s Captive Portal component, is reportedly actively exploited in the wild, and a linked blog post outlines mitigation steps.
