VORANT. Threat Intelligence Sign in Get the full feed

PAN-OS Captive Portal RCE flaw exploited pre-patch

high vulnerability

An unpatched buffer overflow in PAN-OS's Authentication Portal lets unauthenticated attackers gain root RCE on Palo Alto firewalls, with limited exploitation already observed.

CISA/MS-ISAC has issued an advisory for CVE-2026-0300, a buffer overflow in the User-ID Authentication Portal (Captive Portal) service of Palo Alto Networks PAN-OS. The flaw allows an unauthenticated remote attacker to send specially crafted packets to achieve arbitrary code execution with root privileges on PA-Series and VM-Series firewalls. No patch is currently available; Palo Alto has indicated a fix is expected around May 13, 2026, and in the meantime recommends restricting Authentication Portal access to trusted zones or disabling the service entirely.

Threat intelligence cited in the advisory indicates limited exploitation has already been observed in the wild, specifically targeting Authentication Portals exposed to untrusted networks or the public internet. Organizations that have followed best practices by restricting portal access to internal networks face significantly reduced risk. Given the wide deployment of PAN-OS firewalls at network perimeters, the combination of unauthenticated root-level RCE, confirmed in-the-wild exploitation, and the absence of a patch makes this a high-priority issue for affected organizations across all sectors, pending vendor remediation.

Mentioned in this report

Vulnerabilities CVE-2026-0300KEV

Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-pan-os-could-allow-for-remote-code-execution_2026-043

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free