Critical Palo Alto Networks PAN-OS Vulnerability Exploited to Gain Root Access
ID: 28cb2c40-aec4-53f5-9165-56c8ea425d86
STIX ID: report--28cb2c40-aec4-53f5-9165-56c8ea425d86
Feed Name: Cyber Press
## Executive summary CVE-2026-0300 is a critical out-of-bounds write vulnerability in the PAN-OS User-ID Authentication (Captive Portal) service that allows unauthenticated attackers to achieve root-level code execution on PA-Series and VM-Series firewalls; CISA has confirmed active exploitation and added the flaw to its Known Exploited Vulnerabilities catalog, urging immediate mitigation (restricting/disabling the portal, applying vendor guidance, and monitoring for device takeover indicators).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
