Briefing

Palo Alto Vulnerability CVE-2026-0300 Exploited for a Month

security
by [email protected] (The Hacker News) · CVE-2026-0300

Patch PAN‑OS to the latest version that fixes CVE‑2026‑0300 immediately.

What to do now

Patch PAN‑OS to the latest version that resolves CVE‑2026‑0300 immediately.

Summary

A critical buffer‑overflow flaw in Palo Alto Networks’ PAN‑OS User‑ID Authentication Portal, identified as CVE‑2026‑0300, has been actively exploited for nearly a month. First observed on 9 April 2026, the vulnerability allows unauthenticated attackers to send oversized input that bypasses bounds checking and execute arbitrary code with root privileges on PA‑Series and VM‑Series firewalls. By 16 April, attackers had successfully injected shellcode, cleaned logs, and established covert SOCKS v5 tunnels using the open‑source Earthworm and ReverseSocks5 tools to maintain remote command and control while bypassing NAT.

The scope of the attack is wide: Shadowserver reports more than 5,800 VM‑Series firewalls online, with 2,466 located in Asia and 1,998 in North America. The flaw does not affect Cloud NGFW or Panorama appliances, and Palo Alto is still working on a fix for the VM‑Series. The vulnerability, rated CVSS 9.3/8.7, is the highest‑severity flaw identified by the vendor and has been chained with other PAN‑OS zero‑days in past incidents.

In response, Palo Alto released a patch on 13 May 2026 but urged customers to act immediately. Until the fix arrives, the company recommends disabling the authentication portal or restricting it to trusted internal zones. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE‑2026‑0300 to its Known Exploited Vulnerabilities catalog and ordered all federal civilian executive‑branch agencies to secure vulnerable firewalls by midnight on 9 May. The advisory includes a quick check for administrators: navigate to Device > User Identification > Authentication Portal Settings and verify whether the portal is enabled.

The incident underscores the importance of timely patch management for critical infrastructure. Palo Alto Networks has warned that the flaw is being actively exploited against firewalls exposed to untrusted IP addresses or the public internet, and that restricting portal access to trusted networks dramatically reduces risk.

Key changes

  • CVE‑2026‑0300 is a buffer overflow in PAN‑OS authentication module
  • Allows unauthenticated remote code execution
  • CVSS score 9.3 when User‑ID Authentication Portal is internet‑exposed
  • Already exploited in the wild
  • Advisory issued by Palo Alto Networks
  • Latest security patch must be applied to mitigate

Affects

enterprise internal

Source angles · 4 perspectives

The Hacker News
Independent angle

Palo Alto PAN-OS Flaw Under Active Exploitation Enables Remote Code Execution

Open
The Hacker News
Independent angle

Palo Alto Networks Discloses Unsuccessful Exploit Attempts on CVE-2026-0300, a Critical PAN-OS Buffer Overflow Vulnerability

Open
Bleeping Computer
Independent angle

Palo Alto Networks warns of firewall RCE zero‑day exploited in attacks

Open
Bleeping Computer
Independent angle

Palo Alto Networks firewall zero‑day exploited for nearly a month

Open

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting