securityaffairs.com 5/7/2026, 7:21:02 AM · via preferred

CISA adds Palo Alto PAN OS flaw CVE-2026-0300 to KEV catalog

CISA adds Palo Alto PAN OS flaw CVE-2026-0300 to KEV catalog

Siemens RUGGEDCOM APE1808 Devices

According to Siemens ProductCERT, a buffer overflow vulnerability in the User-ID Authentication Portal (Captive Portal) service of Palo Alto Networks PAN-OS software could allow an unauthenticated attacker to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls by sending specially crafted packets. The following versions of…

First seen 2026-05-06T05:01:14.381Z · Last seen 2026-05-19T18:01:14.899Z

CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Available

THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a Palo Alto Networks PAN-OS flaw to its Known Exploited Vulnerabilities catalog, tracked as CVE-2026-0300 with a CVSS score of 9.3.

The issue is a buffer overflow that allows unauthenticated remote code execution, particularly when the User-ID portal is exposed to the internet, and is described by the advisory published by Palo Alto Networks as enabling an unauthenticated attacker to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls. This week Palo Alto Networks warned that the vulnerability is being exploited in the wild in a limited fashion, with risk reduced for organisations following best practices.

The affected products include various PAN-OS versions for PAN-OS 12.1, 11.2, 11.1 and 10.2, while Prisma Access remains unaffected, and the issue remains unpatched with fixes expected from 13 May 2026; CISA has ordered federal agencies to remediate by 9 May 2026. According to the binding directive and related guidance, agencies and organisations should review the KEV catalog and prioritize remediation accordingly, even as private organisations are advised to assess their exposure and apply fixes when available.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline