CVE-2026-0300Active Exploitation(paloaltonetworks / pa-1410)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 112 mentions and remains active

Immediate actions

  • Patch paloaltonetworks pa-1410 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.

10.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-05-09. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: - Restrict User-ID Authentication Portal access to only trusted zones. - Disable User-ID Authentication Portal if not required. 5/13/2026: Palo Alto has released a variety of patches. If these are relevant to your environment, please apply the designated patch.

Weakness type (CWE)
CWE-787

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pa-1410
  • pa-1420
  • pa-3410
  • pa-3420

Threat summary

  • Active exploitation appears in 289 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 459 mentions across 38 observed days

What's happening

  • Active exploitation reported across 289 signals
  • Exploit tool or code specified in 15 signals
  • PoC mentioned or linked in 27 signals
  • Patch or workaround mentioned in 181 signals
  • Technical details provided in 336 signals
  • Disclosure: 78 classified signals
  • General: 49 classified signals
  • Peaked 36d ago at 112 mentions (2026-05-06); latest day: 3
  • 459 total mentions across 38 days

Affected systems

Products
pa-1410pa-1420pa-3410pa-3420pa-3430pa-3440pa-410pa-410rpa-410r-5gpa-415

52 versions affected across 50 products

Deep dive

Activity timeline459 mentions / 38d
0285684112Mentions · 2026-05-05: 1Mentions · 2026-05-06: 112Mentions · 2026-05-07: 91Mentions · 2026-05-08: 40Mentions · 2026-05-09: 28Mentions · 2026-05-10: 23Mentions · 2026-05-11: 22Mentions · 2026-05-12: 15Mentions · 2026-05-13: 15Mentions · 2026-05-14: 15Mentions · 2026-05-15: 10Mentions · 2026-05-16: 2Mentions · 2026-05-17: 5Mentions · 2026-05-18: 3Mentions · 2026-05-19: 5Mentions · 2026-05-20: 7Mentions · 2026-05-21: 4Mentions · 2026-05-22: 2Mentions · 2026-05-23: 1Mentions · 2026-05-24: 1Mentions · 2026-05-27: 1Mentions · 2026-05-29: 1Mentions · 2026-05-30: 1Mentions · 2026-05-31: 2Mentions · 2026-06-02: 1Mentions · 2026-06-05: 6Mentions · 2026-06-06: 1Mentions · 2026-06-07: 7Mentions · 2026-06-09: 1Mentions · 2026-06-10: 2Mentions · 2026-06-11: 5Mentions · 2026-06-15: 14Mentions · 2026-06-21: 1Mentions · 2026-06-25: 8Mentions · 2026-06-30: 1Mentions · 2026-07-02: 1Mentions · 2026-07-05: 1Mentions · 2026-07-13: 3PoC Mentioned / Linked · 2026-05-06: 10PoC Mentioned / Linked · 2026-05-07: 3PoC Mentioned / Linked · 2026-05-08: 1PoC Mentioned / Linked · 2026-05-09: 1PoC Mentioned / Linked · 2026-05-10: 1PoC Mentioned / Linked · 2026-05-11: 1PoC Mentioned / Linked · 2026-05-13: 2PoC Mentioned / Linked · 2026-05-15: 2PoC Mentioned / Linked · 2026-05-21: 3PoC Mentioned / Linked · 2026-05-22: 1PoC Mentioned / Linked · 2026-06-06: 1PoC Mentioned / Linked · 2026-06-25: 1Exploit Tool / Code · 2026-05-06: 3Exploit Tool / Code · 2026-05-07: 2Exploit Tool / Code · 2026-05-08: 1Exploit Tool / Code · 2026-05-10: 1Exploit Tool / Code · 2026-05-12: 1Exploit Tool / Code · 2026-05-13: 1Exploit Tool / Code · 2026-05-14: 1Exploit Tool / Code · 2026-05-15: 1Exploit Tool / Code · 2026-05-21: 2Exploit Tool / Code · 2026-05-22: 1Exploit Tool / Code · 2026-06-09: 1Active Exploitation · 2026-05-06: 71Active Exploitation · 2026-05-07: 65Active Exploitation · 2026-05-08: 30Active Exploitation · 2026-05-09: 16Active Exploitation · 2026-05-10: 19Active Exploitation · 2026-05-11: 15Active Exploitation · 2026-05-12: 11Active Exploitation · 2026-05-13: 10Active Exploitation · 2026-05-14: 10Active Exploitation · 2026-05-15: 5Active Exploitation · 2026-05-16: 2Active Exploitation · 2026-05-17: 3Active Exploitation · 2026-05-18: 1Active Exploitation · 2026-05-19: 3Active Exploitation · 2026-05-20: 4Active Exploitation · 2026-05-21: 2Active Exploitation · 2026-05-22: 1Active Exploitation · 2026-05-27: 1Active Exploitation · 2026-06-05: 4Active Exploitation · 2026-06-06: 1Active Exploitation · 2026-06-07: 2Active Exploitation · 2026-06-09: 1Active Exploitation · 2026-06-10: 1Active Exploitation · 2026-06-11: 3Active Exploitation · 2026-06-15: 6Active Exploitation · 2026-06-25: 1Active Exploitation · 2026-07-02: 1Patch / Workaround · 2026-05-06: 51Patch / Workaround · 2026-05-07: 31Patch / Workaround · 2026-05-08: 18Patch / Workaround · 2026-05-09: 13Patch / Workaround · 2026-05-10: 12Patch / Workaround · 2026-05-11: 13Patch / Workaround · 2026-05-12: 5Patch / Workaround · 2026-05-13: 10Patch / Workaround · 2026-05-14: 5Patch / Workaround · 2026-05-15: 1Patch / Workaround · 2026-05-17: 2Patch / Workaround · 2026-05-19: 4Patch / Workaround · 2026-05-20: 3Patch / Workaround · 2026-05-21: 2Patch / Workaround · 2026-05-22: 2Patch / Workaround · 2026-05-23: 1Patch / Workaround · 2026-05-24: 1Patch / Workaround · 2026-05-27: 1Patch / Workaround · 2026-05-31: 1Patch / Workaround · 2026-06-07: 1Patch / Workaround · 2026-06-09: 1Patch / Workaround · 2026-06-10: 1Patch / Workaround · 2026-06-15: 1Patch / Workaround · 2026-06-30: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-06: 91Technical Details · 2026-05-07: 69Technical Details · 2026-05-08: 29Technical Details · 2026-05-09: 19Technical Details · 2026-05-10: 15Technical Details · 2026-05-11: 16Technical Details · 2026-05-12: 10Technical Details · 2026-05-13: 13Technical Details · 2026-05-14: 12Technical Details · 2026-05-15: 8Technical Details · 2026-05-16: 1Technical Details · 2026-05-17: 4Technical Details · 2026-05-18: 1Technical Details · 2026-05-19: 2Technical Details · 2026-05-20: 5Technical Details · 2026-05-21: 2Technical Details · 2026-05-22: 2Technical Details · 2026-05-23: 1Technical Details · 2026-05-24: 1Technical Details · 2026-05-27: 1Technical Details · 2026-05-31: 1Technical Details · 2026-06-05: 5Technical Details · 2026-06-06: 1Technical Details · 2026-06-07: 4Technical Details · 2026-06-09: 1Technical Details · 2026-06-11: 1Technical Details · 2026-06-15: 9Technical Details · 2026-06-21: 1Technical Details · 2026-06-25: 4Technical Details · 2026-06-30: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-05: 1Technical Details · 2026-07-13: 305-0505-0805-1105-1405-1705-2005-2305-2906-0206-0706-1106-2507-0507-13
Signal classification6 categories
Active Exploitation
27459.7%
Disclosure
7817.0%
General
4910.7%
Patch
4710.2%
PoC
102.2%
Disclovery
10.2%
Referenced assets248 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-051
Disclosure1
2026-05-06112
Active Exploitation67Disclosure22Disclovery1General7Patch11PoC4
2026-05-0791
Active Exploitation64Disclosure15General4Patch7PoC1
2026-05-0840
Active Exploitation28Disclosure4General3Patch5
2026-05-0928
Active Exploitation15Disclosure7General2Patch4
2026-05-1023
Active Exploitation19Disclosure1General2Patch1
2026-05-1122
Active Exploitation13Disclosure3General1Patch5
2026-05-1215
Active Exploitation11Disclosure4
2026-05-1315
Active Exploitation9Disclosure1General1Patch4
2026-05-1415
Active Exploitation10Disclosure2General3
2026-05-1510
Active Exploitation5Disclosure4General1
2026-05-162
Active Exploitation2
2026-05-175
Active Exploitation3Disclosure1General1
2026-05-183
Active Exploitation1Disclosure1General1
2026-05-195
Active Exploitation1General1Patch3
2026-05-207
Active Exploitation4Disclosure1Patch2
2026-05-214
Active Exploitation1PoC3
2026-05-222
Active Exploitation1PoC1
2026-05-231
Patch1
2026-05-241
General1
2026-05-271
Patch1
2026-05-291
General1
2026-05-301
General1
2026-05-312
General1Patch1
2026-06-021
General1
2026-06-056
Active Exploitation4General2
2026-06-061
Active Exploitation1
2026-06-077
Active Exploitation2General4Patch1
2026-06-091
Active Exploitation1
2026-06-102
Active Exploitation1General1
2026-06-115
Active Exploitation3General2
2026-06-1514
Active Exploitation6Disclosure4General4
2026-06-211
Disclosure1
2026-06-258
Active Exploitation1Disclosure3General3PoC1
2026-06-301
Patch1
2026-07-021
Active Exploitation1
2026-07-051
General1
2026-07-133
Disclosure3
Full discourse20 posts
  • Cyber Security News@The_Cyber_News
    Active Exploitation

    🚨 Critical Palo Alto Firewalls Vulnerability Exploited in the Wild to Gain Root Access Source: https://cybersecuritynews.com/palo-alto-firewalls-vulnerability-exploited/ Palo Alto Networks has disclosed a critical buffer overflow vulnerability in PAN-OS software, tracked as CVE-2026-0300, that is already being actively exploited in the wild. The flaw carries a CVSS 4.0 score of 9.3 (CRITICAL) and allows unauthenticated attackers to execute arbitrary code with full root privileges on affected PA-Series and VM-Series firewalls, with no credentials, no user interaction, and no special conditions required. The vulnerability resides in the User-ID™ Authentication Portal (also known as Captive Portal) service of PAN-OS. The vulnerability impacts multiple PAN-OS versions across PA-Series and VM-Series firewalls. #cybersecuritynews #vulnerability

    Post summary

    The article reports that CVE-2026-0300, a critical buffer overflow in Palo Alto PAN‑OS, is being actively exploited in the wild to gain root access, but provides no PoC, exploit code, or patch details.

    81861159522182.4K
    67.1K followersView on X
  • International Cyber Digest@IntCyberDigest
    Active Exploitation

    ‼️🚨 CRITICAL: Palo Alto Networks has disclosed CVE-2026-0300, a buffer overflow in PAN-OS that is already being exploited in the wild. CVSS 4.0 score: 9.3. Unauthenticated attackers can hit the User-ID Authentication Portal (the Captive Portal service) with crafted packets and pop a root shell on the firewall. The flaw is an out-of-bounds write (CWE-787) in PA-Series and VM-Series firewalls. Prisma Access, Cloud NGFW, and Panorama are not affected. The vulnerability only triggers when the User-ID Authentication Portal is enabled and reachable from untrusted networks. Affected branches: - PAN-OS 10.2 below 10.2.7-h34, 10.2.10-h36, 10.2.13-h21, 10.2.16-h7, 10.2.18-h6 - PAN-OS 11.1 below 11.1.4-h33, 11.1.6-h32, 11.1.7-h6, 11.1.10-h25, 11.1.13-h5, 11.1.15 - PAN-OS 11.2 below 11.2.4-h17, 11.2.7-h13, 11.2.10-h6, 11.2.12 - PAN-OS 12.1 below 12.1.4-h5, 12.1.7 Patches roll out between May 13 and May 28, 2026. A Threat Prevention signature for PAN-OS 11.1 and above shipped on May 5. Mitigations before patches roll out: - Restrict Authentication Portal access to trusted internal IPs only - Disable the User-ID Authentication Portal entirely if not needed Compromising a perimeter firewall as root opens the door to lateral movement, traffic interception, credential harvesting, and full network takeover. Audit Device > User Identification > Authentication Portal Settings and treat any internet-exposed portal as an emergency.

    Post summary

    CVE-2026-0300 is a critical buffer overflow in Palo Alto PAN‑OS that is already being exploited in the wild to obtain root, with patches and mitigations available.

    10126955814759.6K
    184.6K followersView on X
  • Sans Limite@SansLimit3
    General

    Exposed attacker infrastructure combining #Hermes Agent, #CyberStrikeAI, #SliverC2, and multiple LLMs used for automated CVE targeting, exploit validation, Telegram-based orchestration, and post-exploitation validation workflows. Opendir: 142.171.160[.]137:8888 VULN-MONITOR: 142.171.149[.169:8001 - Real-time 1day/0day RCE tracking across 18 sources🤔 CyberStrikeAI Server: 100.81.245[.29:8080 Chain: FOFA/Shodan recon → AI-assisted target filtering → CVE/PoC enrichment → custom scanner & exploit generation → exploit validation → WebSocket/shell access → post-exploitation environment validation → Telegram-pushed operations. Targeted CVEs: CVE-2026-0300 (Palo Alto PAN-OS) CVE-2024-21762 (FortiOS/FortiProxy SSL-VPN) CVE-2026-33017 (Langflow) CVE-2026-21858 (n8n) CVE-2026-3055 (Citrix ADC/NetScaler) CVE-2026-34486 (Apache Tomcat) CVE-2026-25253 (OpenClaw/Moltbot/Clawdbot) @malwrhunterteam @500mk500 @1ZRR4H @MichalKoczwara

    Post summary

    The post details an attacker’s automated infrastructure targeting multiple CVEs with RCE potential, but it provides no PoC, exploit code, or evidence of active exploitation.

    837223619525.2K
    634 followersView on X
  • Dark Web Informer@DarkWebInformer
    General

    ‼️ Nuclei template for fingerprinting the PAN-OS CVE-2026-0300 zero-day: https://github.com/projectdiscovery/nuclei-templates/blob/25b1082881e20b9eb1a5cf69dca381e736f351da/http/exposed-panels/panos-management-panel.yaml Credit: @rxerium https://t.co/Qxjm1RjGfl

    Post summary

    The tweet shares a Nuclei template used to detect PAN-OS CVE‑2026‑0300 without providing exploit code, patch info, or evidence of active exploitation.

    141021811021.4K
    222.6K followersView on X
  • Rishi@rxerium
    Disclosure

    🚨 Palo Alto has disclosed a zero day: CVE-2026-0300 (CVSS 9.3) - a buffer overflow vulnerability in the Captive Portal service of PAN-OS. Nuclei template for fingerprinting PAN-OS: https://github.com/projectdiscovery/nuclei-templates/blob/25b1082881e20b9eb1a5cf69dca381e736f351da/http/exposed-panels/panos-management-panel.yaml This issue is applicable only to PA-Series and VM-Series firewalls that are configured to use User-ID™ Authentication Portal - Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability. No patches are available yet, only workarounds. Full details and mitigations are in the official advisory. https://security.paloaltonetworks.com/CVE-2026-0300

    Post summary

    Palo Alto has announced CVE-2026-0300 as a zero‑day buffer overflow, providing technical details and available mitigations but no exploit code or evidence of active exploitation.

    24921888428.4K
    3.8K followersView on X
  • Dark Web Informer@DarkWebInformer
    PoC

    ‼️CVE-2026-0300: PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID Authentication Portal CVSS 9.3 PoC: https://github.com/p3Nt3st3r-sTAr/CVE-2026-0300-POC FOFA Query: app="Palo-Alto-pan-os" FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJQYWxvLUFsdG8tcGFuLW9zIg== Results: 32,070 Blog Post: https://www.rapid7.com/blog/post/etr-critical-buffer-overflow-in-palo-alto-networks-pan-os-user-id-authentication-portal-cve-2026-0300/

    Post summary

    CVE-2026-0300 is a high‑scoring buffer overflow vulnerability in Palo Alto PAN‑OS with a publicly shared PoC, yet no evidence of active exploitation or patch status is mentioned.

    34401618018.9K
    223.7K followersView on X
  • Rishi@rxerium
    General

    Detection script for CVE-2026-0300 - honing in on captive portals: https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-0300.yaml Also allows for verification of device models given this issue is only applicable to PA-Series and VM-Series firewalls. https://t.co/t4wFY5wmpx

    Post summary

    A detection script for CVE-2026-0300 targeting captive portals is shared via a GitHub link, noting the issue affects PA-Series and VM-Series firewalls.

    03201166914.5K
    3.8K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 PAN-OS firewalls hit by active exploitation of CVE-2026-0300, enabling unauthenticated RCE with root access. The unpatched flaw targets publicly exposed User-ID portals, affecting multiple versions. Fixes expected May 13, 2026. Read the full story: https://thehackernews.com/2026/05/palo-alto-pan-os-flaw-under-active.html

    Post summary

    PAN‑OS firewalls are being actively exploited via CVE‑2026‑0300, enabling unauthenticated remote code execution with root privileges; a patch is anticipated for May 13, 2026.

    54861351218.6K
    1.8M followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Active Exploitation

    ⚠️ ثغرة خطره في (Palo Alto PAN-OS) برقم (CVE-2026-0300) بتقييم 9.3 . الثغرة حرجة جداً و CISA أضافتها فوراً لقائمة الثغرات المستغلة فعلياً (KEV). اذا تحب تعرف تفاصيل اكثر اقراء التغريدات التاليه: 👇 https://t.co/WkCeXFf5dM

    Post summary

    CVE-2026-0300, a critical Palo Alto PAN‑OS vulnerability rated 9.3, is listed by CISA as actively exploited (KEV) but the text provides no PoC, exploit tool, or patch details.

    471104459.1K
    49.3K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 PAN-OS flaw "CVE-2026-0300" exploited for unauthenticated RCE with root access. Attacks began April 9, achieved within a week, followed by espionage and lateral movement by April 29. Full details and timeline: https://thehackernews.com/2026/05/pan-os-rce-exploit-under-active-use.html

    Post summary

    CVE‑2026‑0300 is being actively exploited, enabling unauthenticated remote code execution with root privileges on PAN‑OS systems.

    32917379.7K
    1.8M followersView on X
  • Clandestine@akaclandestine
    PoC

    GitHub - p3Nt3st3r-sTAr/CVE-2026-0300-POC · GitHub https://github.com/p3Nt3st3r-sTAr/CVE-2026-0300-POC

    Post summary

    A GitHub repository for CVE‑2026‑0300 publishes a proof‑of‑concept, but does not discuss active exploitation, patching, or any false‑positive evaluation.

    112061343.9K
    62.5K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added Palo Alto Networks PAN-OS out-of-bounds write vulnerability CVE-2026-0300 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q for more information. #Cybersecurity #InfoSec https://t.co/dxItrieU6c

    Post summary

    The tweet reports that CVE‑2026‑0300, an out‑of‑bounds write flaw in PAN‑OS, is listed in the DHS Known Exploited Vulnerabilities Catalog, indicating it has been actively exploited in the wild.

    42836578.8K
    299.5K followersView on X
  • watchTowr@watchtowrcyber
    Patch

    🚨 Overnight watchTowr rapidly reacted to CVE-2026-0300, an unauthenticated buffer overflow in Palo Alto PAN-OS User-ID Auth Portal. RCE as root on PA-/VM-Series. No patch. Palo Alto: limited ITW exploitation. Existing watchTowr clients aware of exposure. Reach out for support. https://t.co/zkscfaL5HL

    Post summary

    The tweet warns that CVE-2026-0300, an unauthenticated buffer overflow in Palo Alto PAN-OS User-ID Auth Portal, is being used for limited exploitation in the wild, but no patch exists and users are urged to seek support.

    010058238.5K
    12.2K followersView on X
  • yousukezan@yousukezan
    Active Exploitation

    Palo Alto NetworksのファイアウォールOSであるPAN-OSに、深刻な脆弱性(CVE-2026-0300)が発見され、すでに実際の攻撃で悪用されていることが報告された。この問題はUser-ID認証ポータル(Captive Portal)に存在するバッファオーバーフローで、特別に細工された通信を送ることで未認証の攻撃者でも侵入可能となる。 攻撃が成功すると、ファイアウォール上で任意のコードがroot権限で実行され、通信の傍受や内部ネットワークへの侵入、セキュリティ機能の無効化など、完全な制御を奪われる危険がある。特にインターネットに公開されたポータルを使用している環境ではリスクが高い。一方で、Prisma AccessやCloud NGFWなど一部のサービスは影響を受けない。 修正パッチは順次提供予定だが、即時対応としてポータルへのアクセス制限、不要な機能の無効化、脅威防御機能の有効化などの緩和策が推奨されている。 https://securityonline.info/palo-alto-networks-cve-2026-0300-active-exploitation-captive-portal-rce/

    Post summary

    CVE‑2026‑0300, a buffer‑overflow flaw in PAN‑OS’s Captive Portal, has been actively exploited, enabling unauthenticated attackers to execute arbitrary root‑level code; patches are forthcoming and mitigations are advised.

    016149195.0K
    14.4K followersView on X
  • nekono_nanomotoni@nekono_naha
    Active Exploitation

    CVE-2026-0300 is a PAN-OS zero-day in User-ID Authentication Portal/Captive Portal (6080/6081/6082/tcp). Limited exploitation confirmed; unpatched as of May 7, 2026. My research: 2,986 of 62,616 public PAN-OS servers (4.8%) expose these ports. 2nd image: sample attack surface. https://t.co/vw0Cg2auxT

    Post summary

    CVE-2026-0300 is a zero‑day affecting PAN‑OS User‑ID authentication, with limited active exploitation confirmed and no patch yet available.

    06155217.0K
    6.1K followersView on X
  • mRr3b00t@UK_Daniel_Card
    Patch

    CVE-2026-0300 Restrict interfaces …. You should be doing that where appropriate/possible anyway….. https://t.co/QvPiwhDHfn

    Post summary

    The tweet offers a brief mitigation suggestion—restrict interfaces—for CVE‑2026‑0300, with no technical, exploit, or active exploitation details.

    4101541012.3K
    123.7K followersView on X
  • Simo@SimoKohonen
    General

    No big exploit activity on the recent Palo Alto vuln (CVE-2026-0300), but a decent amount of scanning activity like this "exposure survey" Feels like a lot of these are looking in the wrong direction though, both in terms of ports and paths.. https://t.co/5IDENutlWt

    Post summary

    The author reports limited exploitation but increasing scanning activity for CVE‑2026‑0300, with no PoC, exploit tool, patch, or technical details disclosed.

    38047117.0K
    3.2K followersView on X
  • H4x0r.DZ 🇰🇵@h4x0r_dz
    Disclosure

    CVE-2026-0300 PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID Authentication Portal https://security.paloaltonetworks.com/CVE-2026-0300

    Post summary

    A newly disclosed buffer overflow vulnerability (CVE‑2026‑0300) in Palo Alto Networks' PAN‑OS User‑ID Authentication Portal is highlighted, with basic technical details provided but no indicators of exploitation or mitigations.

    1805194.7K
    81.3K followersView on X
  • Yu F@fj_twt
    Disclosure

    ( ꒪⌓꒪)…リモートからコマンド実行可能ゼロデイのあるNext Generation Firewall、最高かよww 愛おし過ぎてかれこれ10年以上使い続けてるけどw(PA-2050→PA-5050→PA-1420) 10年経ってもNext Generationなのは気のせいだ!囧rz CVE-2026-0300 PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal https://security.paloaltonetworks.com/CVE-2026-0300

    Post summary

    The post announces CVE-2026-0300, a buffer‑overflow flaw in Palo Alto Networks' Next Generation Firewall that permits unauthenticated remote command execution, and links to the vendor advisory.

    39142104.6K
    1.6K followersView on X
  • Sekurak@Sekurak
    Patch

    Uwaga na aktywnie wykorzystywaną podatność w urządzeniach Palo Alto. CVE-2026-0300 ❌ Wycena krytyczności to prawie max w skali CVSS / ❌ Od strony technicznej to Unauthenticated user initiated Buffer Overflow - czyli z poziomu internetu można uzyskać uprawnienia (prawdopodobnie że jako root) na systemie operacyjnym urządzenia. ❌ Producent parę godzin temu wydał łatkę, dodając że luka jest aktywnie wykorzystywana: "Limited exploitation has been observed targeting Palo Alto Networks User-ID™ Authentication Portals that are exposed to untrusted IP addresses and/or the public internet." ✅ Łatajcie swoje urządzenia, zanim przejmą je boty czy inne łobuzy

    Post summary

    The text warns of the actively exploited CVE-2026-0300 buffer overflow in Palo Alto devices, confirms a vendor patch has been issued, and highlights the severity of the vulnerability.

    29143310.6K
    43.9K followersView on X
CPE platform detail211 entries

211 of 211 entries

PartVendorProductVersionTarget SWTarget HW
HWpaloaltonetworkspa-1410---
HWpaloaltonetworkspa-1420---
HWpaloaltonetworkspa-3410---
HWpaloaltonetworkspa-3420---
HWpaloaltonetworkspa-3430---
HWpaloaltonetworkspa-3440---
HWpaloaltonetworkspa-410---
HWpaloaltonetworkspa-410r---
HWpaloaltonetworkspa-410r-5g---
HWpaloaltonetworkspa-415---
HWpaloaltonetworkspa-415-5g---
HWpaloaltonetworkspa-440---
HWpaloaltonetworkspa-445---
HWpaloaltonetworkspa-450---
HWpaloaltonetworkspa-450r---
HWpaloaltonetworkspa-450r-5g---
HWpaloaltonetworkspa-455---
HWpaloaltonetworkspa-455-5g---
HWpaloaltonetworkspa-455r-5g---
HWpaloaltonetworkspa-460---
HWpaloaltonetworkspa-501---
HWpaloaltonetworkspa-505---
HWpaloaltonetworkspa-510---
HWpaloaltonetworkspa-520---
HWpaloaltonetworkspa-540---
HWpaloaltonetworkspa-5410---
HWpaloaltonetworkspa-5420---
HWpaloaltonetworkspa-5430---
HWpaloaltonetworkspa-5440---
HWpaloaltonetworkspa-5445---
HWpaloaltonetworkspa-545-poe---
HWpaloaltonetworkspa-5450---
HWpaloaltonetworkspa-550---
HWpaloaltonetworkspa-5540---
HWpaloaltonetworkspa-555-poe---
HWpaloaltonetworkspa-5550---
HWpaloaltonetworkspa-5560---
HWpaloaltonetworkspa-5570---
HWpaloaltonetworkspa-5580---
HWpaloaltonetworkspa-560---
HWpaloaltonetworkspa-7500---
HWpaloaltonetworkspa-7500-dpc-a---
OSpaloaltonetworkspan-os10.2.0--
OSpaloaltonetworkspan-os10.2.1--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.11--
OSpaloaltonetworkspan-os10.2.12--
OSpaloaltonetworkspan-os10.2.13--
OSpaloaltonetworkspan-os10.2.13--
OSpaloaltonetworkspan-os10.2.13--
OSpaloaltonetworkspan-os10.2.13--
OSpaloaltonetworkspan-os10.2.13--
OSpaloaltonetworkspan-os10.2.13--
OSpaloaltonetworkspan-os10.2.13--
OSpaloaltonetworkspan-os10.2.13--
OSpaloaltonetworkspan-os10.2.13--
OSpaloaltonetworkspan-os10.2.13--
OSpaloaltonetworkspan-os10.2.14--
OSpaloaltonetworkspan-os10.2.15--
OSpaloaltonetworkspan-os10.2.16--
OSpaloaltonetworkspan-os10.2.16--
OSpaloaltonetworkspan-os10.2.16--
OSpaloaltonetworkspan-os10.2.16--
OSpaloaltonetworkspan-os10.2.17--
OSpaloaltonetworkspan-os10.2.18--
OSpaloaltonetworkspan-os10.2.18--
OSpaloaltonetworkspan-os10.2.18--
OSpaloaltonetworkspan-os10.2.2--
OSpaloaltonetworkspan-os10.2.3--
OSpaloaltonetworkspan-os10.2.4--
OSpaloaltonetworkspan-os10.2.5--
OSpaloaltonetworkspan-os10.2.6--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.8--
OSpaloaltonetworkspan-os10.2.9--
OSpaloaltonetworkspan-os11.1.0--
OSpaloaltonetworkspan-os11.1.1--
OSpaloaltonetworkspan-os11.1.10--
OSpaloaltonetworkspan-os11.1.10--
OSpaloaltonetworkspan-os11.1.10--
OSpaloaltonetworkspan-os11.1.10--
OSpaloaltonetworkspan-os11.1.10--
OSpaloaltonetworkspan-os11.1.10--
OSpaloaltonetworkspan-os11.1.10--
OSpaloaltonetworkspan-os11.1.10--
OSpaloaltonetworkspan-os11.1.10--
OSpaloaltonetworkspan-os11.1.11--
OSpaloaltonetworkspan-os11.1.12--
OSpaloaltonetworkspan-os11.1.13--
OSpaloaltonetworkspan-os11.1.13--
OSpaloaltonetworkspan-os11.1.13--
OSpaloaltonetworkspan-os11.1.13--
OSpaloaltonetworkspan-os11.1.14--
OSpaloaltonetworkspan-os11.1.2--
OSpaloaltonetworkspan-os11.1.3--
OSpaloaltonetworkspan-os11.1.4--
OSpaloaltonetworkspan-os11.1.4--
OSpaloaltonetworkspan-os11.1.4--
OSpaloaltonetworkspan-os11.1.4--
OSpaloaltonetworkspan-os11.1.4--
OSpaloaltonetworkspan-os11.1.4--
OSpaloaltonetworkspan-os11.1.4--
OSpaloaltonetworkspan-os11.1.4--
OSpaloaltonetworkspan-os11.1.4--
OSpaloaltonetworkspan-os11.1.4--
OSpaloaltonetworkspan-os11.1.4--
OSpaloaltonetworkspan-os11.1.4--
OSpaloaltonetworkspan-os11.1.4--
OSpaloaltonetworkspan-os11.1.5--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.7--
OSpaloaltonetworkspan-os11.1.7--
OSpaloaltonetworkspan-os11.1.7--
OSpaloaltonetworkspan-os11.1.7--
OSpaloaltonetworkspan-os11.1.8--
OSpaloaltonetworkspan-os11.1.9--
OSpaloaltonetworkspan-os11.2.0--
OSpaloaltonetworkspan-os11.2.1--
OSpaloaltonetworkspan-os11.2.10--
OSpaloaltonetworkspan-os11.2.10--
OSpaloaltonetworkspan-os11.2.10--
OSpaloaltonetworkspan-os11.2.10--
OSpaloaltonetworkspan-os11.2.10--
OSpaloaltonetworkspan-os11.2.10--
OSpaloaltonetworkspan-os11.2.11--
OSpaloaltonetworkspan-os11.2.2--
OSpaloaltonetworkspan-os11.2.3--
OSpaloaltonetworkspan-os11.2.4--
OSpaloaltonetworkspan-os11.2.4--
OSpaloaltonetworkspan-os11.2.4--
OSpaloaltonetworkspan-os11.2.4--
OSpaloaltonetworkspan-os11.2.4--
OSpaloaltonetworkspan-os11.2.4--
OSpaloaltonetworkspan-os11.2.4--
OSpaloaltonetworkspan-os11.2.4--
OSpaloaltonetworkspan-os11.2.4--
OSpaloaltonetworkspan-os11.2.4--
OSpaloaltonetworkspan-os11.2.4--
OSpaloaltonetworkspan-os11.2.4--
OSpaloaltonetworkspan-os11.2.4--
OSpaloaltonetworkspan-os11.2.4--
OSpaloaltonetworkspan-os11.2.5--
OSpaloaltonetworkspan-os11.2.6--
OSpaloaltonetworkspan-os11.2.7--
OSpaloaltonetworkspan-os11.2.7--
OSpaloaltonetworkspan-os11.2.7--
OSpaloaltonetworkspan-os11.2.7--
OSpaloaltonetworkspan-os11.2.7--
OSpaloaltonetworkspan-os11.2.7--
OSpaloaltonetworkspan-os11.2.7--
OSpaloaltonetworkspan-os11.2.7--
OSpaloaltonetworkspan-os11.2.7--
OSpaloaltonetworkspan-os11.2.7--
OSpaloaltonetworkspan-os11.2.8--
OSpaloaltonetworkspan-os11.2.9--
OSpaloaltonetworkspan-os12.1.2--
OSpaloaltonetworkspan-os12.1.3--
OSpaloaltonetworkspan-os12.1.4--
OSpaloaltonetworkspan-os12.1.4--
OSpaloaltonetworkspan-os12.1.4--
OSpaloaltonetworkspan-os12.1.5--
OSpaloaltonetworkspan-os12.1.6--
HWpaloaltonetworksvm-100---
HWpaloaltonetworksvm-300---
HWpaloaltonetworksvm-50---
HWpaloaltonetworksvm-500---
HWpaloaltonetworksvm-700---
HWsiemensruggedcom_ape1808---
OSsiemensruggedcom_ape1808_firmware---

Explore more