Skip to content
COOEY

EXPOSURES › CVE-2026-0300

CVE-2026-0300

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-05-06 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-0300 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildransomwaresupply-chaindata-breachdefault-creds

Palo Alto Networks PAN-OS allows unauthenticated attackers to execute arbitrary root code via an out-of-bounds write in the User-ID Authentication Portal.

This critical vulnerability enables remote code execution with root privileges on firewalls without authentication, directly threatening DIB network perimeters and violating NIST 800-171 confidentiality and integrity controls. Organizations must immediately patch PAN-OS to prevent unauthorized access to sensitive systems.

Shame score — A critical RCE vulnerability in a widely deployed firewall product that allows unauthenticated attackers to gain root access represents a severe security failure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
GCS-HIGH
Palo Alto Networks, Inc.
Ready
Palo Alto Networks Government Cloud Services
Palo Alto Networks, Inc.
Authorized