# Palo Alto Networks disclosed CVE-2026-0300, a buffer overflow in PAN-OS User-ID…

Published: 2026-05-07 · Severity: critical
Canonical: https://vorant.io/reports/dc51c842-a7dd-4d7b-a04f-97edd0b81d64/palo-alto-networks-disclosed-cve-2026-0300-a-buffer-overflow-in-pan-os-user-id

> Palo Alto Networks disclosed CVE-2026-0300, a buffer overflow in PAN-OS User-ID Authentication Portal being actively exploited to execute arbitrary code.

Japan's IPA (Information-technology Promotion Agency) has issued a security alert regarding a critical vulnerability in Palo Alto Networks PAN-OS. The vulnerability, tracked as CVE-2026-0300, is a buffer overflow in the User-ID Authentication Portal component that allows remote attackers to execute arbitrary code on affected devices.

Palo Alto Networks has confirmed active exploitation of this vulnerability in the wild, raising immediate concern for organizations running affected PAN-OS versions. The vendor notes that Prisma Access, Cloud NGFW, and Panorama appliances are not impacted by this flaw.

IPA recommends that administrators immediately verify whether User-ID Authentication Portal is enabled on their systems and review access controls. Organizations should implement available workarounds and prepare for rapid deployment of patches once released by the vendor. Given the confirmed exploitation, this represents a time-sensitive threat requiring immediate attention from network security teams.

## Mentioned in this report

- Vulnerabilities: CVE-2026-0300 (KEV)

Source reporting: https://www.ipa.go.jp/security/security-alert/2026/alert20260508.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/dc51c842-a7dd-4d7b-a04f-97edd0b81d64/palo-alto-networks-disclosed-cve-2026-0300-a-buffer-overflow-in-pan-os-user-id.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
