logo

PAN-OS RCE Exploit Under Active Use Enabling Root Access and Espionage

ID: 82b6faf2-4697-5a7f-9bd0-62e81f23b03f

STIX ID: report--82b6faf2-4697-5a7f-9bd0-62e81f23b03f

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: [email protected] (The Hacker News)

...
...

**Palo Alto Networks disclosed active exploitation of CVE-2026-0300**, a critical buffer-overflow in the PAN-OS User-ID Authentication Portal allowing unauthenticated RCE as root; unsuccessful probes began April 9, 2026 and later led to successful code execution, shellcode injection, AD enumeration, and deployment of EarthWorm and ReverseSocks5 by a suspected state-sponsored cluster (CL-STA-1132), with mitigations and fixes advised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.