Critical PAN-OS Vulnerability Demands Immediate Attention
ID: 27d42ffa-5b16-5c12-adbe-72528dfd0f17
STIX ID: report--27d42ffa-5b16-5c12-adbe-72528dfd0f17
Feed Name: Ransomware ISAC Blog
Joint advisory on CVE-2026-0300: a critical (CVSS 9.3) out-of-bounds buffer overflow in Palo Alto Networks PA-Series and VM-Series PAN-OS (10.2, 11.1, 11.2, 12.1) targeting the USER-ID authentication portal that can yield unauthenticated root access. Limited exploitation has been observed in education, healthcare, and ISP sectors; patches are not expected until at least May 13. Immediate recommendations include monitoring inbound traffic on ports 6080–6082 for anomalous HTTP POSTs (notably oversized Content-Length to /php/uid.php), isolating inbound traffic, using allow lists, monitoring for suspicious outbound connections from firewalls, and applying Palo Alto Threat Prevention signatures and community detection rules when available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
