Nation-state actors exploit Palo Alto PAN-OS zero-day for weeks
ID: f5709778-6b4b-587d-ba7d-b58b490112a5
STIX ID: report--f5709778-6b4b-587d-ba7d-b58b490112a5
Feed Name: Security Affairs
Palo Alto Networks warns that CVE-2026-0300, a buffer overflow in the User-ID Authentication Portal of PAN-OS, is being actively exploited by suspected nation-state actors (CL-STA-1132) to achieve unauthenticated RCE and root access on exposed PA-Series and VM-Series firewalls; attackers used open-source tunneling tools (EarthWorm, ReverseSocks5), harvested credentials to enumerate Active Directory, and deleted logs to conceal their activity, with limited exploitation observed mostly against portals exposed to the public internet and patches expected starting May 13, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
