logo

Palo Alto Networks warns of firewall RCE zero-day exploited in attacks

ID: 1678e3c3-181c-521f-8b16-5cd804ea2e1d

STIX ID: report--1678e3c3-181c-521f-8b16-5cd804ea2e1d

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

Author: Sergiu Gatlan

...
...

Palo Alto Networks has warned of a critical, unpatched PAN-OS User-ID Authentication Portal zero-day (CVE-2026-0300) — a buffer overflow enabling unauthenticated root remote code execution on Internet-exposed PA-Series and VM-Series firewalls. Limited exploitation has been observed in the wild, Shadowserver reports roughly 5,800 exposed VM-series devices, and Palo Alto strongly urges customers to restrict portal access to trusted zones or disable the portal until a patch is released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.