Palo Alto Networks PAN-OS flaw exploited for remote code execution
ID: e4d0102f-d900-51fb-bd19-53ffa0bf3d30
STIX ID: report--e4d0102f-d900-51fb-bd19-53ffa0bf3d30
Feed Name: Security Affairs
Palo Alto Networks has disclosed a critical buffer overflow in the PAN-OS User-ID Authentication Portal (CVE-2026-0300, CVSS 9.3) that enables unauthenticated remote code execution with root privileges; limited exploitation has been observed, primarily against portals exposed to the public internet. The advisory lists affected PAN-OS versions across 10.x–12.x, confirms Prisma Access/Cloud NGFW/ Panorama are not impacted, recommends restricting portal access to trusted internal IPs, and indicates fixes will be released starting May 13, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
