logo

Nation-state actors exploit Palo Alto PAN-OS zero-day for weeks

ID: f5709778-6b4b-587d-ba7d-b58b490112a5

STIX ID: report--f5709778-6b4b-587d-ba7d-b58b490112a5

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Pierluigi Paganini

...
...

Palo Alto Networks warns that CVE-2026-0300, a buffer overflow in the User-ID Authentication Portal of PAN-OS, is being actively exploited by suspected nation-state actors (CL-STA-1132) to achieve unauthenticated RCE and root access on exposed PA-Series and VM-Series firewalls; attackers used open-source tunneling tools (EarthWorm, ReverseSocks5), harvested credentials to enumerate Active Directory, and deleted logs to conceal their activity, with limited exploitation observed mostly against portals exposed to the public internet and patches expected starting May 13, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.