logo

Critical PAN-OS Vulnerability Demands Immediate Attention

ID: 04f80a54-1ba0-543d-bb95-ca3293f996d2

STIX ID: report--04f80a54-1ba0-543d-bb95-ca3293f996d2

Feed Name: Ransomware ISAC Blog

Threat Score
85/100

Date Published: 2026-05-06

Date Updated: 2026-08-21

Author: [email protected] (Reyben Cortes)

...
...

A joint advisory warns of CVE-2026-0300, a critical (CVSS 9.3) out-of-bounds buffer overflow in Palo Alto PA-Series and VM-Series firewalls' USER-ID authentication portal that can yield unauthenticated root access. Affected PAN-OS versions include 10.2, 11.1, 11.2, and 12.1; limited exploitation has been observed across education, healthcare, and ISP sectors and patches are not expected until May 13, so organizations should monitor ports 6080–6082 for oversized HTTP POSTs to /php/uid.php, isolate inbound traffic, apply allow lists, watch for suspicious outbound connections, and update Threat Prevention signatures and community detection rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.