VORANT. Threat Intelligence Sign in Get the full feed

PAN-OS User-ID Portal Flaw Under Attack

high vulnerability

A buffer overflow vulnerability in Palo Alto Networks PAN-OS User-ID Authentication Portal is being actively exploited to achieve remote code execution.

IPA has issued an alert regarding CVE-2026-0300, a buffer overflow vulnerability affecting the User-ID Authentication Portal component of Palo Alto Networks' PAN-OS. The vendor has confirmed that the vulnerability is already being exploited in the wild by remote attackers, who could leverage it to execute arbitrary code on affected devices. Prisma Access, Cloud NGFW, and Panorama appliances are reportedly not affected by this issue.

Organizations using PAN-OS are urged to check whether the User-ID Authentication Portal feature is enabled and review access restrictions, applying vendor-recommended mitigations if they are exposed. IPA also recommends closely monitoring for vendor patches and applying updates promptly once available, given the active exploitation and potential for expanding attacks.

Mentioned in this report

Vulnerabilities CVE-2026-0300KEV

Source reporting: https://www.ipa.go.jp/security/security-alert/2026/alert20260508.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free