logo

PAN-OS Flaw CVE-2026-0300 Exposes Firewalls to Remote Code Execution

ID: f977e13b-b965-5208-b92d-4fca2e478d56

STIX ID: report--f977e13b-b965-5208-b92d-4fca2e478d56

Feed Name: The Cyber Express

Threat Score
90/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

Author: Ashish Khaitan

...
...

A critical buffer overflow (CVE-2026-0300) in the PAN-OS User-ID Authentication (Captive Portal) enables unauthenticated remote code execution with root privileges (CVSS 9.3) and has been observed in limited active exploitation; the report enumerates impacted PAN-OS versions, scheduled patches (mid–late May 2026), and mitigation steps including restricting or disabling the portal and limiting access to trusted IPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.