CISA warns Palo Alto PAN-OS flaw is being exploited to gain root access
CISA has warned that attackers are exploiting a critical Palo Alto Networks PAN-OS vulnerability that can give them root-level control of affected firewalls. The flaw, tracked as CVE-2026-0300, affects PA-Series and VM-Series firewalls when the User-ID Authentication Portal is enabled and reachable from untrusted networks.
The vulnerability is an unauthenticated buffer overflow in the User-ID Authentication Portal, also known as Captive Portal. Attackers can exploit it by sending specially crafted packets to the exposed portal.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
Successful exploitation can allow remote code execution with root privileges. That level of access can fully compromise a firewall, which makes the issue urgent for organizations that expose the affected portal to the internet.
Why CISA added CVE-2026-0300 to its exploited list
CISA added CVE-2026-0300 to its Known Exploited Vulnerabilities catalog on May 6, 2026, after evidence showed active exploitation. Federal civilian agencies must apply vendor mitigations or stop using affected systems by May 9, 2026.
Palo Alto Networks also confirmed limited exploitation targeting User-ID Authentication Portals exposed to untrusted IP addresses or the public internet. The company rates the vulnerability as critical with a CVSS 4.0 score of 9.3.
The flaw is especially serious because it requires no username, no password, and no user interaction. If the portal is exposed, an attacker can target it directly over the network.
At a glance
| Item | Details |
|---|---|
| CVE | CVE-2026-0300 |
| Product | Palo Alto Networks PAN-OS |
| Affected devices | PA-Series and VM-Series firewalls |
| Affected feature | User-ID Authentication Portal, also known as Captive Portal |
| Vulnerability type | Out-of-bounds write, CWE-787 |
| Severity | Critical, CVSS 4.0 score of 9.3 |
| Impact | Unauthenticated remote code execution with root privileges |
| Exploitation status | Limited exploitation observed in the wild |
Which products are affected
CVE-2026-0300 affects PA-Series and VM-Series firewalls running vulnerable PAN-OS versions. The issue only applies when User-ID Authentication Portal is enabled and exposed through an interface that can receive untrusted traffic.
Palo Alto Networks says Prisma Access, Cloud NGFW, and Panorama appliances are not affected. That distinction matters because the risk depends on both the product and the firewall configuration.
Administrators can check exposure by reviewing User-ID Authentication Portal settings and interface management profiles. Any portal reachable from the public internet or untrusted zones should receive immediate attention.
Affected PAN-OS versions and fix timing
| PAN-OS branch | Affected versions | Fixed versions or release timing |
|---|---|---|
| PAN-OS 12.1 | Versions below 12.1.4-h5 and 12.1.7 | Fixes expected on May 13 and May 28, 2026 |
| PAN-OS 11.2 | Versions below 11.2.4-h17, 11.2.7-h13, 11.2.10-h6, and 11.2.12 | Fixes expected on May 13 and May 28, 2026 |
| PAN-OS 11.1 | Versions below 11.1.4-h33, 11.1.6-h32, 11.1.7-h6, 11.1.10-h25, 11.1.13-h5, and 11.1.15 | Fixes expected on May 13 and May 28, 2026 |
| PAN-OS 10.2 | Versions below 10.2.7-h34, 10.2.10-h36, 10.2.13-h21, 10.2.16-h7, and 10.2.18-h6 | Fixes expected on May 13 and May 28, 2026 |
What attackers can do after exploitation
Root access on a firewall gives attackers a powerful position. They can run commands, change files, hide activity, intercept network traffic, and use the firewall as a launch point for deeper intrusion.
Unit 42 said it is tracking a likely state-sponsored cluster as CL-STA-1132. The attacker exploited CVE-2026-0300 to achieve remote code execution and inject shellcode into an nginx worker process.
The observed post-exploitation activity included tunneling tools such as EarthWorm and ReverseSocks5, Active Directory enumeration using credentials likely obtained from the firewall, and deletion of logs and other evidence.
Why exposed firewall portals are high-risk
Network edge devices are attractive targets because they sit between the internet and internal systems. They often handle sensitive traffic and may hold credentials or service accounts that attackers can reuse.
Firewalls also sit outside many endpoint security layers. If attackers compromise them, defenders may have fewer normal endpoint signals to detect the intrusion.
This is why CISA and Palo Alto Networks both recommend immediate mitigation. Waiting only for firmware updates may leave exposed systems vulnerable during the active exploitation window.
Immediate mitigation steps
- Check whether User-ID Authentication Portal is enabled.
- Confirm whether the portal is reachable from the internet or untrusted networks.
- Restrict User-ID Authentication Portal access to trusted internal zones only.
- Disable User-ID Authentication Portal if the organization does not need it.
- Disable response pages on external Layer 3 interfaces that can receive untrusted traffic.
- Enable Threat ID 510019 if Threat Prevention is licensed and supported.
- Prepare to apply fixed PAN-OS versions as soon as they become available.
- Review firewall logs, crash files, nginx activity, and administrator actions for compromise signs.
What defenders should investigate
Organizations should not treat mitigation as the only task. Since active exploitation has already occurred, exposed environments should also check whether attackers reached their devices before controls changed.
Security teams should review unusual process activity, crash artifacts, missing logs, unexpected outbound connections, suspicious tunnels, and unexplained Active Directory queries from firewall-related accounts.
They should also rotate credentials that the firewall could access or store if compromise indicators appear. If attackers obtained valid credentials from the firewall, they may continue activity even after the vulnerable portal is restricted.
Why this flaw needs emergency handling
CVE-2026-0300 combines several high-risk conditions. It affects perimeter firewalls, allows unauthenticated remote code execution, grants root privileges, and has already been exploited in the wild.
That combination makes the vulnerability more dangerous than a typical patch-cycle issue. Any internet-exposed User-ID Authentication Portal should be treated as an emergency remediation priority.
The safest path is to reduce exposure immediately, check for compromise, and deploy fixed PAN-OS releases when Palo Alto Networks publishes them for the affected branch.
FAQ
No. Palo Alto Networks says Prisma Access, Cloud NGFW, and Panorama appliances are not affected by CVE-2026-0300.
CVE-2026-0300 is a critical buffer overflow vulnerability in the PAN-OS User-ID Authentication Portal. It can allow unauthenticated attackers to execute code with root privileges on affected firewalls.
CISA added the flaw to its Known Exploited Vulnerabilities catalog because attackers are exploiting it in real-world attacks.
The issue affects PA-Series and VM-Series firewalls running vulnerable PAN-OS versions when User-ID Authentication Portal is enabled and exposed to untrusted networks.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages