logo

CVE-2026-0300 Enables Root RCE in PAN-OS Captive Portal

ID: 23120b36-54c8-5be1-9200-ab6439a52aa9

STIX ID: report--23120b36-54c8-5be1-9200-ab6439a52aa9

Feed Name: SOCRadar Blog

Threat Score
80/100

Date Published: 2026-05-06

Date Updated: 2026-05-07

Author: Ameer Owda

...
...

**CVE-2026-0300:** A critical (CVSS 9.3) pre-authentication buffer overflow in PAN-OS User-ID Authentication Portal (Captive Portal) can allow unauthenticated attackers to achieve root RCE on PA-Series and VM-Series firewalls when the portal is enabled and reachable from untrusted networks; limited exploitation has been observed. Mitigations: restrict or disable the Authentication Portal, apply available Threat Prevention signatures, and upgrade to fixed PAN-OS releases listed in the advisory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.