What is CVE-2026-0300?
A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.
Timeline
- 2026-05-06Published to the U.S. National Vulnerability Database (NVD)
- 2026-05-06Added to the CISA Known Exploited Vulnerabilities (KEV) catalog
- 2026-05-07First covered in a defend.network daily briefing
- 2026-05-09CISA federal remediation deadline (BOD 22-01)
- 2026-06-17NVD record last updated
CISA Known Exploited Vulnerability
Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
Affected product
Palo Alto Networks PAN-OS
NVD also lists CPE entries for: Paloaltonetworks Pan-Os, Paloaltonetworks Pa-1410, Paloaltonetworks Pa-1420, Paloaltonetworks Pa-3410, Paloaltonetworks Pa-3420
Remediation Steps
- Obtain and review security advisory from vendor or CISA
- Prioritize patching based on exposed asset inventory and business criticality
- Verify all systems are updated and validated
- Monitor for related indicators of compromise
- Document patching timeline and completion status
References
- https://security.paloaltonetworks.com/CVE-2026-0300
- https://cert-portal.siemens.com/productcert/html/ssa-967325.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-0300
- https://www.cve.org/CVERecord?id=CVE-2026-0300
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://nvd.nist.gov/vuln/detail/CVE-2026-0300
Referenced in our briefings & reports
Browse all tracked CVEs in the defend.network CVE database →