CVE detail
CVE-2026-0300
A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 4.9
Why it matters now
Mention timeline
- Total mentions
- 4
- within the 30d window
- Peak daily
- 2
- highest bucket
Evidence
Source links by recency
20 source links · newest first
- The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposureTenable
n campaign is part of a broader seven-incident agentic AI threat cluster that also includes JADEPUFFER, which exploited CVE-2025-3248 in the Langflow AI workflow platform for automated database extortion, and knaithe/KnYuan, a Chinese-speaking operator assessed by Unit 42 with moderate confidence, using the same AI agent framework for autonomous vulne
vendorwww.tenable.comAug 15, 2026, 1:36 AM - Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability ExploitsInfosecurity Magazine
ritizing vulnerabilities by attack surface. This research led the agent to pivot to seven higher-value vulnerabilities: CVE-2026-33017 (CVSS rating: 9.8): Langflow vulnerability with autonomous exploitation attempt (failed — auto_login disabled) CVE-2026-21858 (CVSS rating: 10.0): n8n Workflow Automation vulnerability with autonomous exploitation attem
newswww.infosecurity-magazine.comJul 31, 2026, 3:00 PM - ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More StoriesThe Hacker News
rrying out an AI-enabled autonomous hacking campaign, targeting infrastructure using seven vulnerabilities in Langflow (CVE-2026-33017), n8n (CVE-2026-21858, CVE-2025-68613), Citrix NetScaler (CVE-2026-3055), Apache Tomcat (CVE-2026-34486), Marimo Notebook (CVE-2026-39987), Palo Alto Networks PAN-OS (CVE-2026-0300), and Microsoft Windows IKE Extensions
newsthehackernews.comJul 30, 2026, 3:25 PM task. Figure 1. Autonomous attack flow observed in Hermes Agent session (May 7, 2026). Phase 1: Langflow Exploitation (CVE-2026-33017) DeepSeek identified a Langflow vulnerability ( CVE-2026-33017 , CVSS 9.8) and autonomously attempted exploitation through the following steps: Downloading the public PoC exploit from GitHub Enumerating 84 Langflow inst
vendorunit42.paloaltonetworks.comJul 30, 2026, 10:00 AM- CVE-2026-0300Horizon3.ai
CVE-2026-0300 enables unauthenticated remote code execution in PAN-OS, posing a critical risk to enterprise and government networks.
exploithorizon3.aiMay 15, 2026, 5:12 PM - 11th May – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 11th May, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Instructure, the US education technology company behind the Canvas learning platform, has confirmed a major data breach affecting its cloud-hosted environment. Exposed data reportedly includes student and staff records and private messages, while […]
vendorresearch.checkpoint.comMay 11, 2026, 12:49 PM - Week in review: cPanel vulnerability actively exploited, DigiCert breach, LinkedIn job scamsHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Your work apps are quietly handing 19 data points to someone Office work in 2026 relies on mobile apps used alongside personal tools like banking and messaging. Ten widely used workplace apps, including Gmail, Microsoft Teams, Zoom, Slack, and Notion, have over 12.5 billion Google Play downloads. Research from Incogni shows these apps collect an average of 19 data points … More →
newswww.helpnetsecurity.comMay 10, 2026, 8:00 AM Palo Alto Networks warns that a critical zero-day vulnerability has been discovered in the PAN-OS firewall system. The vulnerability has already been exploited by suspected state-sponsored hackers for nearly a month, reports Bleeping Computer. The vulnerability, CVE-2026-0300, is located in the User-ID Authentication Portal (also known as the Captive Portal) and allows attackers to execute […]
newswww.csoonline.comMay 8, 2026, 1:19 AM- Nation-state actors exploit Palo Alto PAN-OS zero-day for weeksSecurity Affairs
Palo Alto says hackers exploited PAN-OS zero-day CVE-2026-0300 for weeks, gaining root access to exposed firewalls and hiding traces. Palo Alto Networks warned that suspected state-sponsored hackers have been exploiting the critical PAN-OS zero-day CVE-2026-0300 for nearly a month. After exploiting the flaw, attackers deployed tunneling tools such as EarthWorm and ReverseSocks5, used stolen credentials […]
newssecurityaffairs.comMay 7, 2026, 8:44 PM The cybersecurity firm has not explicitly accused China of being behind the attack, but the evidence suggests it was.
newswww.securityweek.comMay 7, 2026, 3:31 PMPalo Alto Networks believes the in-the-wild exploitation of a zero-day vulnerability (CVE-2026-0300) in its firewalls is likely the work of state-sponsored threat actors. A flaw with no patch (yet) CVE-2026-0300 is a buffer overflow vulnerability in the User-ID Authentication Portal service of Palo Alto Networks PAN-OS software, and can be exploited by unauthenticated attackers sending specially crafted packets to internet-facing User-ID Authentication Portals. The flaw affects Palo Alto Networks’ PA-Series and VM-Series firewalls, and the … More →
newswww.helpnetsecurity.comMay 7, 2026, 11:39 AMPalo Alto Networks is warning customers about a critical buffer overflow vulnerability affecting its PAN-OS user-ID authentication portal that is already being exploited in the wild. The flaw allows attackers to execute arbitrary code with root privileges on exposed firewalls, the company said in a security advisory. PAN-OS is the software that runs all Palo […]
newswww.csoonline.comMay 7, 2026, 11:13 AM- U.S. CISA adds a flaw in Palo Alto Networks PAN-OS to its Known Exploited Vulnerabilities catalogSecurity Affairs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Palo Alto Networks PAN-OS to its Known Exploited Vulnerabilities catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in the Palo Alto Networks PAN-OS, tracked as CVE-2026-0300 (CVSS score of 9.3), to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is a buffer […]
newssecurityaffairs.comMay 7, 2026, 6:51 AM Unit 42 details CVE-2026-0300, a buffer overflow vulnerability in the PAN-OS User-ID Authentication Portal. Read now for details.
vendorunit42.paloaltonetworks.comMay 7, 2026, 12:00 AMNo excerpt available.
Exploitwww.cisa.govMay 6, 2026, 7:16 PM- https://cert-portal.siemens.com/productcert/html/ssa-967325.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comMay 6, 2026, 7:16 PM - https://security.paloaltonetworks.com/CVE-2026-0300security.paloaltonetworks.com
No excerpt available.
Exploitsecurity.paloaltonetworks.comMay 6, 2026, 7:16 PM A critical vulnerability (CVE-2026-0300) affecting Palo Alto Networks firewalls is being actively exploited by attackers, the security company acknowledged today, and urged customers to implement mitigations as they are still working on fixes. About CVE-2026-0300 CVE-2026-0300 is a buffer overflow vulnerability in the User-ID Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software. The portal enables user identification for unknown traffic, i.e., situations where the firewall cannot automatically map an IP address … More →
newswww.helpnetsecurity.comMay 6, 2026, 9:51 AMPalo Alto Networks warns of a critical PAN-OS flaw (CVE-2026-0300) that is under active attack, allowing unauthenticated remote code execution. Palo Alto Networks has warned that a critical PAN-OS vulnerability, tracked as CVE-2026-0300 (CVSS score of 9.3), is actively exploited in the wild. The flaw is a buffer overflow that allows unauthenticated remote code execution, […]
newssecurityaffairs.comMay 6, 2026, 8:52 AMCVE-2026-0300 affects the Captive Portal service of PAN-OS software on PA and VM series firewalls.
newswww.securityweek.comMay 6, 2026, 4:46 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.80 · max 2 stars
- ridhinva/panos-captive-portal-rceMedium confidencegithubRepository topic discovery2 starsDiscovered Aug 7, 2026, 8:50 PM
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-0288CVSS 7.2 · High
Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network…
- CVE-2026-0263CVSS 7.2 · High
A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to execute arbitrary code with elev…
- CVE-2024-9468CVSS 8.2 · High
A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to crash PAN-OS due to a crafted packet through the data plane, resultin…
- CVE-2021-3064CVSS 9.8 · Critical
A memory corruption vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an unauthenticated network-based attacker to disrupt system…
- CVE-2021-3056CVSS 8.8 · High
A memory corruption vulnerability in Palo Alto Networks PAN-OS GlobalProtect Clientless VPN enables an authenticated attacker to execute arbitrary code with root user privileges d…
- CVE-2020-2027CVSS 7.2 · High
A buffer overflow vulnerability in the authd component of the PAN-OS management server allows authenticated administrators to disrupt system processes and potentially execute arbi…