VORANT. Threat Intelligence Sign in Get the full feed

PAN-OS User-ID Portal exploited via CVE-2026-0300

critical vulnerability

Palo Alto Networks' PAN-OS User-ID Authentication Portal contains an actively exploited buffer overflow vulnerability allowing remote code execution.

Japan's Information-technology Promotion Agency (IPA) has issued an advisory regarding a buffer overflow vulnerability (CVE-2026-0300) in Palo Alto Networks' PAN-OS User-ID Authentication Portal. The vulnerability allows remote attackers to execute arbitrary code on affected devices.

Palo Alto Networks has confirmed active exploitation of this vulnerability in the wild. Organizations are urged to immediately verify whether the User-ID Authentication Portal is enabled and assess their access-control configurations. Affected deployments should implement available workarounds while awaiting patches.

Prisma Access, Cloud NGFW, and Panorama appliances are not affected by this vulnerability. IPA recommends organizations closely monitor vendor advisories and prepare to rapidly deploy patches when they become available.

Mentioned in this report

Vulnerabilities CVE-2026-0300KEV

Source reporting: https://www.ipa.go.jp/security/security-alert/2026/alert20260508.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free