CVE Tools

Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution

Palo Alto Unit 42By Justin Moore, Unit 427 min read

Reported exploitedPAN-OSCL-STA-1132PA-Series firewalls
Read at Palo Alto Unit 42

Below is the opening; the full story is at Palo Alto Unit 42.

From Palo Alto Unit 42

Executive Summary

On May 6, 2026, Palo Alto Networks released a CVE-2026-0300">security advisory for CVE-2026-0300, identifying a buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software. Vulnerable systems allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.…

Continue at Palo Alto Unit 42

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store