logo

CISA Issues Warning Over Palo Alto PAN-OS Flaw Enabling Root-Level Access

ID: 2878e6a5-b707-57ad-807b-431fb9197d09

STIX ID: report--2878e6a5-b707-57ad-807b-431fb9197d09

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Divya

...
...

CISA has issued an urgent advisory for a critical PAN-OS vulnerability (CVE-2026-0300): an unauthenticated out-of-bounds write in the User-ID Authentication (Captive Portal) that can allow remote code execution. The flaw was added to CISA's Known Exploited Vulnerabilities list with a May 9, 2026 mitigation deadline for federal agencies; Palo Alto has not released a patch, so administrators are urged to restrict access to or disable the Captive Portal until a fix is available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.