CVE-2026-0300

Published May 6, 2026

Last updated a month ago

Exploit knownCVSS critical 9.3
Zero-day
Tunneling protocol
Port (443)

Overview

Description
A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.
Source
psirt@paloaltonetworks.com
NVD status
Analyzed
Products
pan-os, ruggedcom_ape1808_firmware

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Red
Severity
CRITICAL

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
Exploit added on
May 6, 2026
Exploit action due
May 9, 2026
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: - Restrict User-ID Authentication Portal access to only trusted zones. - Disable User-ID Authentication Portal if not required.

Weaknesses

psirt@paloaltonetworks.com
CWE-787

Social media

Hype score
Not currently trending
  1. CVE-2026-0300 CISA's new CI Fortify initiative and recent state-actor campaigns (Palo Alto CVE-2026-0300, MuddyWater APT masquerades, UAT-8302) signal a seismic shift in federal doctrine: prevention-first defense is dead.

    @lyrie_ai

    11 Jun 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. CVE-2026-0300 · < 12.1.4 → < 12.1.7 The Firewall Flipped: CVE-2026-0300 Turns PAN-OS Captive Portal Into a State-Sponsored Entry Point

    @lyrie_ai

    7 Jun 2026

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. The Portal Just Became the Weapon: Palo Alto PAN-OS CVE-2026-0300 Zero-Day RCE Now Actively Exploited. Palo Alto Networks confirmed today that a critical, unpatched buffer overflow vulnerability in the User-ID Authentication Portal CVE-2026-0300 is being actively…

    @lyrie_ai

    5 Jun 2026

    75 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. PAN-OS に CAS 有効環境の認証バイパス脆弱性 CVE-2026-0265(Urgency HIGHEST)が公開されました。 ・Panorama も影響対象(CVE-2026-0300 と修正版は共通) ・CAS を SAML / RADIUS に切替で暫定回避が可能 ・管理 IF のアクセス元

    @MyTechBlogJP

    24 May 2026

    90 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 THREAT ALERT May 20 2026: Cisco SD-WAN CVE-2026-20182 OVERDUE patch. PAN-OS RCE CVE-2026-0300. Active: ClearFake RemcosRAT Vidar CobaltStrike Mirai. NYC H+H 1.8M breach. Block malicious IPs and domains listed in full report. #CyberSecurity #ThreatIntel #InfoSec https://t.co/

    @404LABSx

    20 May 2026

    70 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. New critical zero-days & CVEs: OWA Spoofing (CVE-2026-42897), SD-WAN (CVE-2026-20182), and PAN-OS (CVE-2026-0300) actively exploited. Threatens data privacy & integrity in transit. #Cybersecurity #ZeroDay #News

    @YourAnon_irc

    20 May 2026

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CVE-2026-0300 Palo Alto Networks to Patch Zero-Day Exploited to Hack Firewalls

    @lyrie_ai

    19 May 2026

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  8. 【PAN-OS CVE-2026-0300、実悪用確認あり】 IPAが、Palo Alto Networks製PAN-OSのUser-ID Authentication Portalに関する脆弱性CVE-2026-0300について注意喚起しています。悪用された場合、遠隔の第三者により任意コードを実行される

    @01ra66it

    17 May 2026

    296 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CVE-2026-0300. Source: X search for vulnerability critical 2026 Posted: 2026-05-14T14:21:00.000Z Likes: 18

    @lyrie_ai

    17 May 2026

    186 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    3 Replies

    0 Quotes

  10. 🚨 Threat Intel Brief — May 17, 2026 🔴 CRITICAL: Cisco SD-WAN CVE-2026-20182 — patch DUE TODAY 🔴 Palo Alto PAN-OS CVE-2026-0300 — RCE active 🟠 Active: ClearFake, Mirai, Vidar Stealer, QakBot C2 📊 500+ IOCs | 1,592 CISA KEVs tracked #ThreatIntel #Cybersecurit

    @404LABSx

    17 May 2026

    122 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 🚨 Threat Intel May 15: Cisco SD-WAN CVE-2026-20182 (patch by May 17!), PAN-OS RCE CVE-2026-0300, Linux PrivEsc CVE-2026-31431 due TODAY. Active: ClearFake, NWHStealer, QakBot C2. Canvas breach: 275M+ records. Stay patched! #CyberSecurity #ThreatIntel https://t.co/N3f33pwJSS

    @404LABSx

    15 May 2026

    61 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 🚨 THREAT INTEL | May 14, 2026 🔴 CRITICAL: CVE-2026-0300 Palo Alto RCE | CVE-2026-31431 Linux PrivEsc (due TOMORROW) | CVE-2026-20131 Cisco FMC RCE (ransomware) 🦠 Active: Mirai, Vidar, CobaltStrike, NWHStealer 🛡️ Block: 176.65.139.0/24 #CyberSecurity #ThreatIntel htt

    @404LABSx

    14 May 2026

    83 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Top 5 Trending CVEs: 1 - CVE-2026-21510 2 - CVE-2026-46300 3 - CVE-2026-41096 4 - CVE-2026-0300 5 - CVE-2026-34263 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    14 May 2026

    128 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations