CVE-2026-0300

Confirmed PUBLISHED

PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal

Palo Alto Networks · Cloud NGFW, PAN-OS, Prisma Access

1 day faster than CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.3 Critical EPSS 36.2%

At a Glance

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.

cisa edge
CVE Published
May 06, 2026
Exploitation Reported
Jun 01, 2026
CVSS
9.3 Critical
EPSS
36.2%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
Siemens
RUGGEDCOM APE1808

0 to < *

Affected
Palo Alto Networks
Cloud NGFW

All

Unaffected
Palo Alto Networks
PAN-OS

12.1.0 to < 12.1.7

Changed to unaffected at 12.1.7

Changed to unaffected at 12.1.4-h5

Affected
Palo Alto Networks
PAN-OS

11.2.0 to < 11.2.12

Changed to unaffected at 11.2.12

Changed to unaffected at 11.2.10-h6

Changed to unaffected at 11.2.7-h13

Changed to unaffected at 11.2.4-h17

Affected
Palo Alto Networks
PAN-OS

11.1.0 to < 11.1.15

Changed to unaffected at 11.1.15

Changed to unaffected at 11.1.13-h5

Changed to unaffected at 11.1.10-h25

Changed to unaffected at 11.1.7-h6

Changed to unaffected at 11.1.6-h32

Changed to unaffected at 11.1.4-h33

Affected
Palo Alto Networks
PAN-OS

10.2.0 to < 10.2.18-h6

Changed to unaffected at 10.2.18-h6

Changed to unaffected at 10.2.16-h7

Changed to unaffected at 10.2.13-h21

Changed to unaffected at 10.2.10-h36

Changed to unaffected at 10.2.7-h34

Affected
Palo Alto Networks
Prisma Access

All

Unaffected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.