logo

CVE-2026-0300: Palo Alto PAN-OS Zero-Day Enables Root RCE on Exposed Firewalls

ID: 7d90cb69-7f64-581a-8aef-714f1bdb6be9

STIX ID: report--7d90cb69-7f64-581a-8aef-714f1bdb6be9

Feed Name: SOC Prime Blog

Threat Score
90/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

Author: SOC Prime Team

...
...

CVE-2026-0300 is a critical buffer-overflow vulnerability in Palo Alto PAN-OS’s User-ID Authentication (Captive) Portal that allows unauthenticated attackers to achieve remote code execution as root on PA-Series and VM-Series firewalls when the portal is enabled and reachable from untrusted networks; limited in-the-wild exploitation has been observed, and immediate mitigations include restricting or disabling the portal and applying vendor patches as they become available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.