Skip to main content
Mallory
Back to intelligence
actively-exploited-vulnerabilityperimeter-device-exposurewidely-deployed-product-advisoryembedded-device-vulnerability

Active Exploitation of PAN-OS Captive Portal Flaw Gives Attackers Root on Firewalls

Updated 17d agoFirst seen May 6, 202628 sources

Palo Alto Networks disclosed CVE-2026-0300, a critical buffer overflow in the PAN-OS User-ID Authentication Portal (also called the Captive Portal) that is being exploited in the wild to achieve unauthenticated remote code execution with root privileges. The flaw is an out-of-bounds write triggered by specially crafted packets and affects exposed PA-Series and VM-Series firewalls running multiple PAN-OS 10.2, 11.1, 11.2, and 12.1 versions. Palo Alto assigned the issue a CVSS 9.3 when the portal is reachable from the public internet or other untrusted networks, and 8.7 when access is limited to trusted internal IP addresses.

The company said observed attacks have focused on Authentication Portal instances exposed to untrusted IP addresses, while Prisma Access, Cloud NGFW, and Panorama are not affected. At disclosure, fixes were not yet broadly available, with patch releases scheduled to begin in mid-May and continue through late May 2026. Palo Alto urged customers to immediately restrict portal access to trusted zones or internal IPs, or disable the Authentication Portal if it is not required, and said a Threat Prevention Signature for PAN-OS 11.1 and later was released as an added mitigation layer.

Share:
Active Exploitation of PAN-OS Captive Portal Flaw Gives Attackers Root on Firewalls
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
May 6, 202624d ago

CISA sets May 9 remediation deadline for CVE-2026-0300

After adding CVE-2026-0300 to the KEV catalog, CISA required Federal Civilian Executive Branch agencies to remediate the actively exploited Palo Alto PAN-OS flaw by May 9, 2026, under Binding Operational Directive 22-01. The agency urged immediate mitigations because vendor patches were still pending.

CISA Warns of Palo Alto PAN-OS Vulnerability Exploited to Gain Root Access

CISA adds CVE-2026-0300 to Known Exploited Vulnerabilities catalog

CISA added Palo Alto Networks PAN-OS CVE-2026-0300 to its Known Exploited Vulnerabilities Catalog, formally recognizing the flaw as exploited in the wild. The agency directed organizations to apply vendor mitigations, follow BOD 22-01 guidance for cloud services, or discontinue use if mitigations were unavailable.

Add Updated KEV Files for 2026-05-06 · cisagov/kev-data@7075827 · GitHub

Palo Alto announces patch rollout schedule for affected PAN-OS versions

Alongside the disclosure, Palo Alto said fixes for affected PAN-OS 10.2, 11.1, 11.2, and 12.1 versions would begin rolling out between May 13 and May 28, 2026. Until patches are available, customers were advised to restrict portal access to trusted internal IPs or disable the Authentication Portal if unused.

Palo Alto discloses CVE-2026-0300 under active exploitation

Palo Alto Networks disclosed CVE-2026-0300, a critical unauthenticated buffer overflow in the PAN-OS User-ID Authentication Portal that can lead to remote code execution with root privileges. The company said the flaw is being exploited in the wild, particularly against internet-exposed or otherwise untrusted portal deployments.

May 5, 202625d ago

Palo Alto releases Threat Prevention Signature for CVE-2026-0300

Palo Alto Networks released a Threat Prevention Signature for PAN-OS 11.1 and later as a mitigation for CVE-2026-0300. The signature was made available ahead of full software patches to help reduce exploitation risk.

Apr 9, 20262mo ago

Palo Alto links CVE-2026-0300 exploitation to CL-STA-1132 activity

Palo Alto Networks said suspected state-sponsored cluster CL-STA-1132 began attempting to exploit CVE-2026-0300 on April 9, 2026, and achieved successful remote code execution about a week later by injecting shellcode into an nginx worker process. The company also described post-exploitation behavior including log deletion, Active Directory enumeration, and deployment of EarthWorm and ReverseSocks5 on a second device by April 29.

PAN-OS RCE Exploit Under Active Use Enabling Root Access and Espionage
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.