www.securityweek.com 5/7/2026, 3:51:15 PM · via preferred

Palo Alto Zero-Day Exploited in Campaign Bearing Hallmarks of Chinese State Hacking

Palo Alto Zero-Day Exploited in Campaign Bearing Hallmarks of Chinese State Hacking

Siemens RUGGEDCOM APE1808 Devices

According to Siemens ProductCERT, a buffer overflow vulnerability in the User-ID Authentication Portal (Captive Portal) service of Palo Alto Networks PAN-OS software could allow an unauthenticated attacker to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls by sending specially crafted packets. The following versions of…

First seen 2026-05-06T05:01:14.381Z · Last seen 2026-05-19T18:01:14.899Z

CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Available
Threat Actor
CL-STA-1132

SECURITYWEEK reports that Palo Alto Networks has disclosed exploitation of the recently disclosed zero-day affecting its PA and VM series firewalls, tracked as CVE-2026-0300, with unauthenticated remote code execution and root privileges. The firm said patches are slated for May 13 and May 28, while providing mitigations in the interim.

A blog post described the in-the-wild exploitation, and Palo Alto notes a “likely state-sponsored” threat group, tracked as CL-STA-1132, was behind the attack, with first exploitation attempts seen on April 9 and successful remote code execution a week later accompanied by Nginx worker process shellcode injection.

Following compromise, the attackers allegedly cleaned logs, deleting nginx crash entries and core dumps, and four days later deployed tools with root privileges before conducting Active Directory enumeration using the firewall’s service account credentials. The attackers reportedly used Earthworm and ReverseSocks5 to establish covert channels and bypass firewalls, with the report emphasising that the activity aligns with Chinese state hacking hallmarks, though Palo Alto stops short of a direct country attribution.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline