logo

A Vulnerability in PAN-OS Could Allow for Remote Code Execution

ID: c5aeedff-a2b4-5d28-a4b2-a38102088932

STIX ID: report--c5aeedff-a2b4-5d28-a4b2-a38102088932

Feed Name: CISecurity.org Advisories

Threat Score
85/100

Date Published: 2026-05-06

Date Updated: 2026-05-07

...
...

A buffer-overflow vulnerability (CVE-2026-0300) in the PAN-OS User-ID Authentication Portal (Captive Portal) can allow an unauthenticated remote attacker to achieve arbitrary code execution with root privileges on PA‑Series and VM‑Series firewalls. No patch was available at the time of the advisory; Palo Alto recommends restricting portal access to trusted zones or disabling the portal until a patch is released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.