# PAN-OS User-ID Portal exploited via CVE-2026-0300

Published: 2026-05-07 · Severity: critical
Canonical: https://vorant.io/reports/be4ba851-59e6-5db4-92f3-bbe235561396/pan-os-user-id-portal-exploited-via-cve-2026-0300

> Palo Alto Networks' PAN-OS User-ID Authentication Portal contains an actively exploited buffer overflow vulnerability allowing remote code execution.

Japan's Information-technology Promotion Agency (IPA) has issued an advisory regarding a buffer overflow vulnerability (CVE-2026-0300) in Palo Alto Networks' PAN-OS User-ID Authentication Portal. The vulnerability allows remote attackers to execute arbitrary code on affected devices.

Palo Alto Networks has confirmed active exploitation of this vulnerability in the wild. Organizations are urged to immediately verify whether the User-ID Authentication Portal is enabled and assess their access-control configurations. Affected deployments should implement available workarounds while awaiting patches.

Prisma Access, Cloud NGFW, and Panorama appliances are not affected by this vulnerability. IPA recommends organizations closely monitor vendor advisories and prepare to rapidly deploy patches when they become available.

## Mentioned in this report

- Vulnerabilities: CVE-2026-0300 (KEV)

Source reporting: https://www.ipa.go.jp/security/security-alert/2026/alert20260508.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/be4ba851-59e6-5db4-92f3-bbe235561396/pan-os-user-id-portal-exploited-via-cve-2026-0300.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
