U.S. CISA adds a flaw in Palo Alto Networks PAN-OS to its Known Exploited Vulnerabilities catalog
ID: 9aaad10b-55b2-5e8c-b153-30e9708ad0c8
STIX ID: report--9aaad10b-55b2-5e8c-b153-30e9708ad0c8
Feed Name: Security Affairs
CISA has added CVE-2026-0300 (CVSS 9.3), a buffer overflow in Palo Alto PAN-OS User-ID Authentication Portal that allows unauthenticated remote code execution, to its Known Exploited Vulnerabilities catalog. Palo Alto reports limited active exploitation against portals exposed to the public internet, publishes impacted/unaffected version details, recommends restricting portal access as a mitigation, and expects fixes in mid‑May 2026 while federal agencies are ordered to remediate by May 9, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
