Palo Alto Networks warns of firewall RCE zero-day exploited in attacks
ID: 1678e3c3-181c-521f-8b16-5cd804ea2e1d
STIX ID: report--1678e3c3-181c-521f-8b16-5cd804ea2e1d
Feed Name: Bleeping Computer
Palo Alto Networks has warned of a critical, unpatched PAN-OS User-ID Authentication Portal zero-day (CVE-2026-0300) — a buffer overflow enabling unauthenticated root remote code execution on Internet-exposed PA-Series and VM-Series firewalls. Limited exploitation has been observed in the wild, Shadowserver reports roughly 5,800 exposed VM-series devices, and Palo Alto strongly urges customers to restrict portal access to trusted zones or disable the portal until a patch is released.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
