logo

CVE-2026-0300: Palo Alto PAN-OS Zero-Day Enables Root RCE on Exposed Firewalls

ID: 4c8c9677-b76b-5c5c-a94d-06076950edd5

STIX ID: report--4c8c9677-b76b-5c5c-a94d-06076950edd5

Feed Name: SOC Prime Blog

Threat Score
90/100

Date Published: 2026-05-06

Date Updated: 2026-05-07

Author: SOC Prime Team

...
...

**Executive summary:** CVE-2026-0300 is a critical (CVSS 9.3) buffer overflow in Palo Alto PAN‑OS User‑ID Authentication (Captive Portal) that enables unauthenticated remote code execution as root on PA‑Series and VM‑Series firewalls when the portal is enabled and reachable from untrusted networks; limited active exploitation has been observed, so organizations should restrict or disable portal access, narrow allowed source IP ranges, and prioritize applying Palo Alto's fixes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.