Briefing

Palo Alto Networks Warns of Firewall RCE Zero‑Day Exploited in Attacks

security
by Sergiu Gatlan · CVE-2026-0300

Check your firewall configuration and restrict or disable the User‑ID Authentication Portal until a patch is released.

What to do now

Check your firewall settings and restrict or disable the User‑ID Authentication Portal until a patch is released.

Summary

Palo Alto Networks has issued an advisory for CVE‑2026‑0300, a critical‑severity zero‑day vulnerability in the PAN‑OS User‑ID Authentication Portal (also known as the Captive Portal). The flaw is a buffer overflow that allows unauthenticated attackers to execute arbitrary code with root privileges on Internet‑exposed PA‑Series and VM‑Series firewalls via specially crafted packets. Shadowserver reports that over 5,800 VM‑Series firewalls are exposed online, with the majority located in Asia (2,466) and North America (1,998). The advisory notes that limited exploitation has been observed targeting exposed User‑ID portals, and that customers who restrict the portal to trusted internal networks are at a greatly reduced risk.

Palo Alto Networks recommends that administrators check whether the vulnerable service is enabled by navigating to Device > User Identification > Authentication Portal Settings and either restricting the portal to trusted zones or disabling it entirely. A patch is not yet available, so the company urges customers to apply the mitigation immediately. The zero‑day follows a history of PAN‑OS vulnerabilities, including a November 2024 DoS flaw that forced firewalls to reboot and a February 2025 exploitation of three other PAN‑OS flaws.

The firm serves more than 70,000 customers worldwide, including 90 % of Fortune 10 companies and most major U.S. banks, underscoring the potential impact of this vulnerability on critical infrastructure.

Key changes

  • CVE‑2026‑0300 is a buffer overflow in PAN‑OS User‑ID Authentication Portal
  • It allows unauthenticated attackers to execute arbitrary code with root on PA‑Series and VM‑Series firewalls
  • Over 5,800 VM‑Series firewalls are exposed online according to Shadowserver
  • Mitigation: restrict the portal to trusted zones or disable it via Device > User Identification > Authentication Portal Settings
  • No patch is available yet; Palo Alto recommends immediate mitigation
  • The vulnerability follows a history of PAN‑OS zero‑days and DoS flaws
  • Palo Alto serves 70,000+ customers, including 90 % of Fortune 10 companies
  • The advisory highlights the risk to critical infrastructure

Affects

enterprise

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting