CISA warns Palo Alto PAN-OS flaw is being exploited to gain root access


CISA has warned that attackers are exploiting a critical Palo Alto Networks PAN-OS vulnerability that can give them root-level control of affected firewalls. The flaw, tracked as CVE-2026-0300, affects PA-Series and VM-Series firewalls when the User-ID Authentication Portal is enabled and reachable from untrusted networks.

The vulnerability is an unauthenticated buffer overflow in the User-ID Authentication Portal, also known as Captive Portal. Attackers can exploit it by sending specially crafted packets to the exposed portal.

Successful exploitation can allow remote code execution with root privileges. That level of access can fully compromise a firewall, which makes the issue urgent for organizations that expose the affected portal to the internet.

Why CISA added CVE-2026-0300 to its exploited list

CISA added CVE-2026-0300 to its Known Exploited Vulnerabilities catalog on May 6, 2026, after evidence showed active exploitation. Federal civilian agencies must apply vendor mitigations or stop using affected systems by May 9, 2026.

Palo Alto Networks also confirmed limited exploitation targeting User-ID Authentication Portals exposed to untrusted IP addresses or the public internet. The company rates the vulnerability as critical with a CVSS 4.0 score of 9.3.

The flaw is especially serious because it requires no username, no password, and no user interaction. If the portal is exposed, an attacker can target it directly over the network.

At a glance

ItemDetails
CVECVE-2026-0300
ProductPalo Alto Networks PAN-OS
Affected devicesPA-Series and VM-Series firewalls
Affected featureUser-ID Authentication Portal, also known as Captive Portal
Vulnerability typeOut-of-bounds write, CWE-787
SeverityCritical, CVSS 4.0 score of 9.3
ImpactUnauthenticated remote code execution with root privileges
Exploitation statusLimited exploitation observed in the wild

Which products are affected

CVE-2026-0300 affects PA-Series and VM-Series firewalls running vulnerable PAN-OS versions. The issue only applies when User-ID Authentication Portal is enabled and exposed through an interface that can receive untrusted traffic.

Palo Alto Networks says Prisma Access, Cloud NGFW, and Panorama appliances are not affected. That distinction matters because the risk depends on both the product and the firewall configuration.

Administrators can check exposure by reviewing User-ID Authentication Portal settings and interface management profiles. Any portal reachable from the public internet or untrusted zones should receive immediate attention.

Affected PAN-OS versions and fix timing

PAN-OS branchAffected versionsFixed versions or release timing
PAN-OS 12.1Versions below 12.1.4-h5 and 12.1.7Fixes expected on May 13 and May 28, 2026
PAN-OS 11.2Versions below 11.2.4-h17, 11.2.7-h13, 11.2.10-h6, and 11.2.12Fixes expected on May 13 and May 28, 2026
PAN-OS 11.1Versions below 11.1.4-h33, 11.1.6-h32, 11.1.7-h6, 11.1.10-h25, 11.1.13-h5, and 11.1.15Fixes expected on May 13 and May 28, 2026
PAN-OS 10.2Versions below 10.2.7-h34, 10.2.10-h36, 10.2.13-h21, 10.2.16-h7, and 10.2.18-h6Fixes expected on May 13 and May 28, 2026

What attackers can do after exploitation

Root access on a firewall gives attackers a powerful position. They can run commands, change files, hide activity, intercept network traffic, and use the firewall as a launch point for deeper intrusion.

Unit 42 said it is tracking a likely state-sponsored cluster as CL-STA-1132. The attacker exploited CVE-2026-0300 to achieve remote code execution and inject shellcode into an nginx worker process.

The observed post-exploitation activity included tunneling tools such as EarthWorm and ReverseSocks5, Active Directory enumeration using credentials likely obtained from the firewall, and deletion of logs and other evidence.

Why exposed firewall portals are high-risk

Network edge devices are attractive targets because they sit between the internet and internal systems. They often handle sensitive traffic and may hold credentials or service accounts that attackers can reuse.

Firewalls also sit outside many endpoint security layers. If attackers compromise them, defenders may have fewer normal endpoint signals to detect the intrusion.

This is why CISA and Palo Alto Networks both recommend immediate mitigation. Waiting only for firmware updates may leave exposed systems vulnerable during the active exploitation window.

Immediate mitigation steps

  • Check whether User-ID Authentication Portal is enabled.
  • Confirm whether the portal is reachable from the internet or untrusted networks.
  • Restrict User-ID Authentication Portal access to trusted internal zones only.
  • Disable User-ID Authentication Portal if the organization does not need it.
  • Disable response pages on external Layer 3 interfaces that can receive untrusted traffic.
  • Enable Threat ID 510019 if Threat Prevention is licensed and supported.
  • Prepare to apply fixed PAN-OS versions as soon as they become available.
  • Review firewall logs, crash files, nginx activity, and administrator actions for compromise signs.

What defenders should investigate

Organizations should not treat mitigation as the only task. Since active exploitation has already occurred, exposed environments should also check whether attackers reached their devices before controls changed.

Security teams should review unusual process activity, crash artifacts, missing logs, unexpected outbound connections, suspicious tunnels, and unexplained Active Directory queries from firewall-related accounts.

They should also rotate credentials that the firewall could access or store if compromise indicators appear. If attackers obtained valid credentials from the firewall, they may continue activity even after the vulnerable portal is restricted.

Why this flaw needs emergency handling

CVE-2026-0300 combines several high-risk conditions. It affects perimeter firewalls, allows unauthenticated remote code execution, grants root privileges, and has already been exploited in the wild.

That combination makes the vulnerability more dangerous than a typical patch-cycle issue. Any internet-exposed User-ID Authentication Portal should be treated as an emergency remediation priority.

The safest path is to reduce exposure immediately, check for compromise, and deploy fixed PAN-OS releases when Palo Alto Networks publishes them for the affected branch.

FAQ

Are Prisma Access, Cloud NGFW, and Panorama affected?

No. Palo Alto Networks says Prisma Access, Cloud NGFW, and Panorama appliances are not affected by CVE-2026-0300.

What is CVE-2026-0300?

CVE-2026-0300 is a critical buffer overflow vulnerability in the PAN-OS User-ID Authentication Portal. It can allow unauthenticated attackers to execute code with root privileges on affected firewalls.

Why did CISA issue a warning?

CISA added the flaw to its Known Exploited Vulnerabilities catalog because attackers are exploiting it in real-world attacks.

Which Palo Alto devices are affected?

The issue affects PA-Series and VM-Series firewalls running vulnerable PAN-OS versions when User-ID Authentication Portal is enabled and exposed to untrusted networks.

Readers help support VPNCentral. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more

User forum

0 messages