VORANT. Threat Intelligence Sign in Get the full feed

Critical buffer overflow in PAN-OS Authentication Portal allows unauthenticated remote…

critical vulnerability

Critical buffer overflow in PAN-OS Authentication Portal allows unauthenticated remote code execution with root privileges; limited exploitation observed in the wild.

A buffer overflow vulnerability (CVE-2026-0300) has been identified in the PAN-OS Authentication Portal service affecting multiple versions of Palo Alto Networks' firewall operating system. The flaw allows unauthenticated remote attackers to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls by sending specially crafted packets to exposed User-ID Authentication Portals. Limited exploitation has been observed targeting portals exposed to untrusted IP addresses and the public internet.

The vulnerability affects PAN-OS versions 10.2, 11.1, 11.2, and 12.1 across multiple patch levels. At the time of the advisory, no patch was available, though Palo Alto planned a release for May 13, 2026. Organizations following best practices by restricting Authentication Portal access to trusted internal networks face significantly reduced risk. Palo Alto recommends restricting portal access to trusted zones or disabling the service entirely if not required as interim mitigations.

This represents a critical risk to organizations with internet-facing Authentication Portals, particularly given the root-level code execution capability and active exploitation. The vulnerability exploits a public-facing application and provides initial access to enterprise networks, making it an attractive target for threat actors seeking to compromise network perimeter defenses.

Mentioned in this report

Vulnerabilities CVE-2026-0300KEV

Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-pan-os-could-allow-for-remote-code-execution_2026-043

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free