logo

Critical Buffer Overflow Vulnerability in PAN-OS Exploited in-the-Wild

ID: 33682f95-03f2-57b6-bdd8-64bb78298070

STIX ID: report--33682f95-03f2-57b6-bdd8-64bb78298070

Feed Name: Wiz Blog

Threat Score
88/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

Author: Merav Bar

...
...

**Executive summary:** A critical unauthenticated remote code execution vulnerability (CVE-2026-0300) in the PAN-OS User-ID Authentication Portal (ports 6081/6082) enables attackers to achieve root code execution; Palo Alto reports a CVSS of 9.3 and limited in-the-wild exploitation, multiple PAN-OS branches/versions are affected, and recommended mitigations include immediate patching, restricting or disabling the portal, and avoiding Internet exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.