Critical Palo Alto Firewall Flaw Exploited to Gain Root Access
ID: 827120d3-237e-5d0c-9713-893ea44c3532
STIX ID: report--827120d3-237e-5d0c-9713-893ea44c3532
Feed Name: Cyber Press
Palo Alto Networks has warned of CVE-2026-0300, a critical CWE-787 buffer overflow in the PAN-OS User-ID Authentication Portal that allows unauthenticated remote attackers to achieve full root code execution on PA-Series and VM-Series firewalls. The flaw (CVSS 9.3) is actively exploited in limited campaigns, affects multiple PAN-OS branches (10.2, 11.1, 11.2, 12.1), and has mitigations including restricting portal access, disabling the service, and deploying an interim Threat Prevention signature while official firmware patches are rolled out between May 13–28, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
