Palo Alto Networks firewall zero-day exploited for nearly a month
ID: 31d7557d-b036-58cd-b7b8-4eeabd571266
STIX ID: report--31d7557d-b036-58cd-b7b8-4eeabd571266
Feed Name: Bleeping Computer
Palo Alto Networks disclosed an actively exploited PAN-OS zero-day (CVE-2026-0300) in the User-ID Authentication Portal allowing unauthenticated RCE with root privileges on internet-exposed PA- and VM-series firewalls; suspected state-sponsored actors (cluster CL-STA-1132) achieved successful exploitation, performed log cleanup, and deployed tunneling tools (EarthWorm, ReverseSocks5). Shadowserver reports over 5,400 exposed VM firewalls, Palo Alto is preparing patches, and CISA has added the CVE to its KEV catalog and ordered federal mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
