CISA Issues Warning Over Palo Alto PAN-OS Flaw Enabling Root-Level Access
ID: 2878e6a5-b707-57ad-807b-431fb9197d09
STIX ID: report--2878e6a5-b707-57ad-807b-431fb9197d09
Feed Name: GBHackers
Threat Score
CISA has issued an urgent advisory for a critical PAN-OS vulnerability (CVE-2026-0300): an unauthenticated out-of-bounds write in the User-ID Authentication (Captive Portal) that can allow remote code execution. The flaw was added to CISA's Known Exploited Vulnerabilities list with a May 9, 2026 mitigation deadline for federal agencies; Palo Alto has not released a patch, so administrators are urged to restrict access to or disable the Captive Portal until a fix is available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
