www.rapid7.com 5/6/2026, 2:11:07 PM · via preferred

Critical Buffer Overflow in Palo Alto Networks PAN-OS User-ID Authentication Portal (CVE-2026-0300)

Siemens RUGGEDCOM APE1808 Devices

According to Siemens ProductCERT, a buffer overflow vulnerability in the User-ID Authentication Portal (Captive Portal) service of Palo Alto Networks PAN-OS software could allow an unauthenticated attacker to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls by sending specially crafted packets. The following versions of…

First seen 2026-05-06T05:01:14.381Z · Last seen 2026-05-19T18:01:14.899Z

CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

ON 6 May 2026, Palo Alto Networks published a security advisory for CVE-2026-0300, a critical unauthenticated buffer overflow in the User-ID Authentication Portal (also known as Captive Portal) affecting PAN-OS PA-Series and VM-Series firewall appliances.

The flaw, rated CVSSv4 9.3, enables an unauthenticated remote attacker to send specially crafted packets to a device with the Authentication Portal enabled, achieving arbitrary code execution with root privileges; Prisma Access, Cloud NGFW and Panorama are not affected.

Palo Alto Networks has confirmed limited exploitation in the wild targeting Authentication Portals exposed to untrusted IP addresses or the public internet, and there are no patches yet, with fixed versions expected to begin rolling out on 13 May 2026 and continuing through 28 May 2026. Shodan identifies approximately 225,000 internet-facing PAN-OS instances, highlighting a significant attack surface.

Rapid7 urges organisations running affected PAN-OS versions with the User-ID Authentication Portal enabled to apply the available workarounds immediately and prioritise patching as soon as fixed versions become available, according to the Palo Alto Networks advisory.

View Primary Source Via www.rapid7.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline