logo

State-Sponsored Actors Weaponize Critical PAN-OS Zero-Day for Root

ID: 5168906e-f908-5fb5-ba1a-77f02f18d520

STIX ID: report--5168906e-f908-5fb5-ba1a-77f02f18d520

Feed Name: securityonline.info

Threat Score
92/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Ddos

...
...

Palo Alto Networks disclosed a critical buffer overflow (CVE-2026-0300) in the PAN-OS User-ID Authentication Portal (Captive Portal) that allows unauthenticated remote code execution with root privileges on PA-Series and VM-Series firewalls; Unit 42 reports this zero-day has been weaponized by a likely nation-state cluster (CL-STA-1132) engaged in long-term, stealthy intrusions, performing credential theft, tunneling with public tools, log destruction, and identity-focused lateral movement. Immediate mitigations recommended are to restrict portal access to trusted internal IPs, disable the portal if unused, and apply PAN-OS patches immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.