CVE-2026-0300

Palo Alto Networks PAN-OS · CISA Known Exploited Vulnerability · NIST NVD ↗

Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.

2026-05-06
Published
2026-05-09
CISA remediate by

Sources