Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitygovernment-vulnerability-catalogperimeter-device-exposurewidely-deployed-product-advisory

Critical PAN-OS Captive Portal Flaw Let Attackers Gain Root on Firewalls

Updated 29d agoFirst seen May 24, 20267 sources

Palo Alto Networks disclosed CVE-2026-0300, a critical CWE-787 out-of-bounds write in the PAN-OS User-ID Authentication Portal, also known as the Captive Portal, that allows an unauthenticated attacker to achieve remote code execution as root on affected PA-Series and VM-Series firewalls. The flaw was reported as actively exploited in the wild and added to CISA's Known Exploited Vulnerabilities catalog, with exploitation observed against portals reachable from untrusted networks or the public internet. Palo Alto said Prisma Access, Cloud NGFW, and Panorama are not affected, while vulnerable PAN-OS branches included 10.2, 11.1, 11.2, and 12.1 below fixed releases.

Reporting on observed intrusions said attackers used the firewall access for shellcode injection into nginx worker processes, credential extraction, Active Directory enumeration, outbound tunneling with tools such as EarthWorm and ReverseSocks5, internal pivoting, and anti-forensic log cleanup. Palo Alto began releasing patches in staged waves and urged defenders to disable the Captive Portal if unused or restrict it to trusted IPs and zones, enable available threat-prevention signatures, and treat previously exposed devices as potentially fully compromised by auditing configurations, checking admin accounts and SSH keys, rotating credentials, and monitoring for persistence or suspicious outbound connections.

Share:
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
May 13, 20261mo ago

Initial PAN-OS fixes begin rolling out

Palo Alto Networks began releasing patches for CVE-2026-0300 in staged waves starting on May 13, 2026, for affected PAN-OS branches. The company continued to recommend restricting Authentication Portal access to trusted zones or disabling the feature until systems were fully remediated.

May 6, 20262mo ago

Palo Alto publishes staged patch schedule for affected PAN-OS branches

At disclosure, Palo Alto said fixes were not yet available but published estimated release dates for patched PAN-OS versions. Reporting said the first wave of patches would begin on May 13, 2026, followed by a second wave on May 28, 2026.

CISA adds CVE-2026-0300 to the KEV catalog

On May 6, 2026, CISA added CVE-2026-0300 to its Known Exploited Vulnerabilities catalog due to active exploitation. The listing set a remediation deadline of May 9, 2026 for affected federal agencies.

Palo Alto discloses CVE-2026-0300 and confirms active exploitation

On May 6, 2026, Palo Alto Networks disclosed CVE-2026-0300 as a critical unauthenticated out-of-bounds write / buffer overflow in the PAN-OS User-ID Authentication Portal that can lead to root-level remote code execution on affected PA-Series and VM-Series firewalls. The vendor said the flaw was being actively exploited in the wild and advised restricting or disabling the Captive Portal where possible.

Apr 16, 20262mo ago

Attackers achieve successful RCE and post-exploitation activity

By April 16, 2026, attackers had achieved remote code execution as root via CVE-2026-0300. Reported follow-on activity included shellcode injection into nginx worker processes, credential extraction, Active Directory enumeration, anti-forensic log cleanup, and outbound tunneling with tools such as EarthWorm and ReverseSocks5.

Apr 9, 20263mo ago

Exploitation of PAN-OS Captive Portal flaw begins

Palo Alto Networks and Unit 42 observed limited in-the-wild exploitation of CVE-2026-0300 starting on April 9, 2026, targeting PAN-OS User-ID Authentication Portals exposed to untrusted networks or the public internet.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

26 LINKEDOpen in app
Threat actors
1 linked
Malware
2 linked
Affected products
9 linked
Pan-OsPrisma AccessCloud NgfwPanoramaVm-SeriesPa-SeriesGlobalprotectGithubCurl
Organizations
13 linked
Palo Alto NetworksInternational Business MachinesGoogleRapid7ElasticAlienvaultCrowdStrikeDarktraceGitHubHelp Net SecurityBlackSwan CybersecurityKodem SecurityBeazley Security
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.