logo

2026-006: Critical Vulnerability in PAN-OS

ID: 944f5b01-6f5f-51b4-b3d4-a99049bf9fd4

STIX ID: report--944f5b01-6f5f-51b4-b3d4-a99049bf9fd4

Feed Name: CERT-EU Security Advisories

Threat Score
85/100

Date Published: 2026-05-06

Date Updated: 2026-05-18

...
...

On 6 May 2026 Palo Alto Networks disclosed CVE-2026-0300, a critical (CVSS 9.3) buffer overflow in the PAN-OS User‑ID Authentication Portal that can allow an unauthenticated attacker to execute arbitrary code as root on PA‑Series and VM‑Series firewalls; limited exploitation was observed and patches are scheduled, with interim mitigations including restricting or disabling the User‑ID Authentication Portal.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.