logo

U.S. CISA adds a flaw in Palo Alto Networks PAN-OS to its Known Exploited Vulnerabilities catalog

ID: 9aaad10b-55b2-5e8c-b153-30e9708ad0c8

STIX ID: report--9aaad10b-55b2-5e8c-b153-30e9708ad0c8

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Pierluigi Paganini

...
...

CISA has added CVE-2026-0300 (CVSS 9.3), a buffer overflow in Palo Alto PAN-OS User-ID Authentication Portal that allows unauthenticated remote code execution, to its Known Exploited Vulnerabilities catalog. Palo Alto reports limited active exploitation against portals exposed to the public internet, publishes impacted/unaffected version details, recommends restricting portal access as a mitigation, and expects fixes in mid‑May 2026 while federal agencies are ordered to remediate by May 9, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.