Skip to main content

CVE detail

CVE-2026-0300

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.

CVSS 9.3 · CriticalBuzz score 79.9KEV listed1 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 79.9

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 4.9
Mention score
30.0
20 evidence mentions in the snapshot
Diversity score
20.0
13 sources across 5 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
4.9
1 repos · best confidence 0.80
Best PoC traction
2
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
4
within the 30d window
Peak daily
2
highest bucket

Evidence

Source links by recency

Newest mentions first
20 source links · newest first
  • n campaign is part of a broader seven-incident agentic AI threat cluster that also includes JADEPUFFER, which exploited CVE-2025-3248 in the Langflow AI workflow platform for automated database extortion, and knaithe/KnYuan, a Chinese-speaking operator assessed by Unit 42 with moderate confidence, using the same AI agent framework for autonomous vulne

    vendorwww.tenable.comAug 15, 2026, 1:36 AM
  • ritizing vulnerabilities by attack surface. This research led the agent to pivot to seven higher-value vulnerabilities: CVE-2026-33017 (CVSS rating: 9.8): Langflow vulnerability with autonomous exploitation attempt (failed — auto_login disabled) CVE-2026-21858 (CVSS rating: 10.0): n8n Workflow Automation vulnerability with autonomous exploitation attem

    newswww.infosecurity-magazine.comJul 31, 2026, 3:00 PM
  • rrying out an AI-enabled autonomous hacking campaign, targeting infrastructure using seven vulnerabilities in Langflow (CVE-2026-33017), n8n (CVE-2026-21858, CVE-2025-68613), Citrix NetScaler (CVE-2026-3055), Apache Tomcat (CVE-2026-34486), Marimo Notebook (CVE-2026-39987), Palo Alto Networks PAN-OS (CVE-2026-0300), and Microsoft Windows IKE Extensions

    newsthehackernews.comJul 30, 2026, 3:25 PM
  • task. Figure 1. Autonomous attack flow observed in Hermes Agent session (May 7, 2026). Phase 1: Langflow Exploitation (CVE-2026-33017) DeepSeek identified a Langflow vulnerability ( CVE-2026-33017 , CVSS 9.8) and autonomously attempted exploitation through the following steps: Downloading the public PoC exploit from GitHub Enumerating 84 Langflow inst

    vendorunit42.paloaltonetworks.comJul 30, 2026, 10:00 AM
  • CVE-2026-0300Horizon3.ai

    CVE-2026-0300 enables unauthenticated remote code execution in PAN-OS, posing a critical risk to enterprise and government networks.

    exploithorizon3.aiMay 15, 2026, 5:12 PM
  • 11th May – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 11th May, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Instructure, the US education technology company behind the Canvas learning platform, has confirmed a major data breach affecting its cloud-hosted environment. Exposed data reportedly includes student and staff records and private messages, while […]

    vendorresearch.checkpoint.comMay 11, 2026, 12:49 PM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Your work apps are quietly handing 19 data points to someone Office work in 2026 relies on mobile apps used alongside personal tools like banking and messaging. Ten widely used workplace apps, including Gmail, Microsoft Teams, Zoom, Slack, and Notion, have over 12.5 billion Google Play downloads. Research from Incogni shows these apps collect an average of 19 data points … More →

    newswww.helpnetsecurity.comMay 10, 2026, 8:00 AM
  • Palo Alto Networks warns that a critical zero-day vulnerability has been discovered in the PAN-OS firewall system. The vulnerability has already been exploited by suspected state-sponsored hackers for nearly a month, reports Bleeping Computer. The vulnerability, CVE-2026-0300, is located in the User-ID Authentication Portal (also known as the Captive Portal) and allows attackers to execute […]

    newswww.csoonline.comMay 8, 2026, 1:19 AM
  • Palo Alto says hackers exploited PAN-OS zero-day CVE-2026-0300 for weeks, gaining root access to exposed firewalls and hiding traces. Palo Alto Networks warned that suspected state-sponsored hackers have been exploiting the critical PAN-OS zero-day CVE-2026-0300 for nearly a month. After exploiting the flaw, attackers deployed tunneling tools such as EarthWorm and ReverseSocks5, used stolen credentials […]

    newssecurityaffairs.comMay 7, 2026, 8:44 PM
  • The cybersecurity firm has not explicitly accused China of being behind the attack, but the evidence suggests it was.

    newswww.securityweek.comMay 7, 2026, 3:31 PM
  • Palo Alto Networks believes the in-the-wild exploitation of a zero-day vulnerability (CVE-2026-0300) in its firewalls is likely the work of state-sponsored threat actors. A flaw with no patch (yet) CVE-2026-0300 is a buffer overflow vulnerability in the User-ID Authentication Portal service of Palo Alto Networks PAN-OS software, and can be exploited by unauthenticated attackers sending specially crafted packets to internet-facing User-ID Authentication Portals. The flaw affects Palo Alto Networks’ PA-Series and VM-Series firewalls, and the … More →

    newswww.helpnetsecurity.comMay 7, 2026, 11:39 AM
  • Palo Alto Networks is warning customers about a critical buffer overflow vulnerability affecting its PAN-OS user-ID authentication portal that is already being exploited in the wild. The flaw allows attackers to execute arbitrary code with root privileges on exposed firewalls, the company said in a security advisory. PAN-OS is the software that runs all Palo […]

    newswww.csoonline.comMay 7, 2026, 11:13 AM
  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Palo Alto Networks PAN-OS to its Known Exploited Vulnerabilities catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in the Palo Alto Networks PAN-OS, tracked as CVE-2026-0300 (CVSS score of 9.3), to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is a buffer […]

    newssecurityaffairs.comMay 7, 2026, 6:51 AM
  • Unit 42 details CVE-2026-0300, a buffer overflow vulnerability in the PAN-OS User-ID Authentication Portal. Read now for details.

    vendorunit42.paloaltonetworks.comMay 7, 2026, 12:00 AM
  • No excerpt available.

    Exploitwww.cisa.govMay 6, 2026, 7:16 PM
  • https://cert-portal.siemens.com/productcert/html/ssa-967325.htmlcert-portal.siemens.com

    No excerpt available.

    Vendor Advisorycert-portal.siemens.comMay 6, 2026, 7:16 PM
  • https://security.paloaltonetworks.com/CVE-2026-0300security.paloaltonetworks.com

    No excerpt available.

    Exploitsecurity.paloaltonetworks.comMay 6, 2026, 7:16 PM
  • A critical vulnerability (CVE-2026-0300) affecting Palo Alto Networks firewalls is being actively exploited by attackers, the security company acknowledged today, and urged customers to implement mitigations as they are still working on fixes. About CVE-2026-0300 CVE-2026-0300 is a buffer overflow vulnerability in the User-ID Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software. The portal enables user identification for unknown traffic, i.e., situations where the firewall cannot automatically map an IP address … More →

    newswww.helpnetsecurity.comMay 6, 2026, 9:51 AM
  • Palo Alto Networks warns of a critical PAN-OS flaw (CVE-2026-0300) that is under active attack, allowing unauthenticated remote code execution. Palo Alto Networks has warned that a critical PAN-OS vulnerability, tracked as CVE-2026-0300 (CVSS score of 9.3), is actively exploited in the wild. The flaw is a buffer overflow that allows unauthenticated remote code execution, […]

    newssecurityaffairs.comMay 6, 2026, 8:52 AM
  • CVE-2026-0300 affects the Captive Portal service of PAN-OS software on PA and VM series firewalls.

    newswww.securityweek.comMay 6, 2026, 4:46 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

1 repository references · best confidence 0.80 · max 2 stars

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2026-0288

    Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-OS software allow an unauthenticated attacker with network…

    CVSS 7.2 · High
    3 mentions
  • CVE-2026-0263

    A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to execute arbitrary code with elev…

    CVSS 7.2 · High
    1 mention
  • CVE-2024-9468

    A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to crash PAN-OS due to a crafted packet through the data plane, resultin…

    CVSS 8.2 · High
  • CVE-2021-3064

    A memory corruption vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an unauthenticated network-based attacker to disrupt system…

    CVSS 9.8 · Critical
    5 mentions
  • CVE-2021-3056

    A memory corruption vulnerability in Palo Alto Networks PAN-OS GlobalProtect Clientless VPN enables an authenticated attacker to execute arbitrary code with root user privileges d…

    CVSS 8.8 · High
  • CVE-2020-2027

    A buffer overflow vulnerability in the authd component of the PAN-OS management server allows authenticated administrators to disrupt system processes and potentially execute arbi…

    CVSS 7.2 · High