logo

Palo Alto Networks firewall zero-day exploited for nearly a month

ID: 31d7557d-b036-58cd-b7b8-4eeabd571266

STIX ID: report--31d7557d-b036-58cd-b7b8-4eeabd571266

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Sergiu Gatlan

...
...

Palo Alto Networks disclosed an actively exploited PAN-OS zero-day (CVE-2026-0300) in the User-ID Authentication Portal allowing unauthenticated RCE with root privileges on internet-exposed PA- and VM-series firewalls; suspected state-sponsored actors (cluster CL-STA-1132) achieved successful exploitation, performed log cleanup, and deployed tunneling tools (EarthWorm, ReverseSocks5). Shadowserver reports over 5,400 exposed VM firewalls, Palo Alto is preparing patches, and CISA has added the CVE to its KEV catalog and ordered federal mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.