logo

Palo Alto Networks Firewall Zero-Day RCE Vulnerability Exploited in the Wild Since April

ID: e4694c8f-a6ad-5963-98be-d341c6b9f519

STIX ID: report--e4694c8f-a6ad-5963-98be-d341c6b9f519

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Guru Baran

...
...

**Active zero-day exploitation of PAN-OS Captive Portal (CVE-2026-0300):** Unit 42 reports a likely state-sponsored campaign (CL-STA-1132) exploiting a buffer overflow in the PAN-OS User-ID Authentication Portal to achieve unauthenticated root RCE, deploy public tunneling tools (EarthWorm, ReverseSocks5), perform AD enumeration and cleanup forensic artifacts; the advisory includes IOCs and immediate mitigations (restrict or disable the Authentication Portal).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.