Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
Palo Alto Networks — Cloud NGFW
A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.
9.3
32.1%
Vector breakdown
- Attack vector
- Network
- Attack complexity
- Low
- Attack requirements
- None
- Privileges required
- None
- User interaction
- None
- Confidentiality (Vulnerable System)
- High
- Integrity (Vulnerable System)
- High
- Availability (Vulnerable System)
- High
- Confidentiality (Subsequent System)
- Low
- Integrity (Subsequent System)
- Low
- Availability (Subsequent System)
- None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:A/AU:Y/R:U/V:C/RE:M/U:Red
- Published
- May 6, 2026
- Modified
- Jul 14, 2026
- Added to KEV
- May 6, 2026
- Federal patch due
- May 9, 2026
CISA required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: - Restrict User-ID Authentication Portal access to only trusted zones. - Disable User-ID Authentication Portal if not required. 5/13/2026: Palo Alto has released a variety of patches. If these are relevant to your environment, please apply the designated patch.
Weakness classification
Proof-of-concept & exploitation references
Weaponization
Public repositories whose name or description references CVE-2026-0300, found via a live GitHub search at request time. These are community-sourced signals, not a verified working exploit - cross-check each one before relying on it, and treat higher star counts and recent activity as (weak) corroboration, not proof.
No public GitHub repositories referencing CVE-2026-0300 were found at last check. Absence here is not proof no exploit exists - see the references below for vendor advisories and write-ups.
References
Frequently asked questions
What is CVE-2026-0300?
A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.
How severe is CVE-2026-0300?
CVE-2026-0300 has a CVSS base score of 9.3 out of 10 (CVSS 4.0).
Is CVE-2026-0300 actively exploited in the wild?
Yes. CVE-2026-0300 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added May 6, 2026, meaning CISA has confirmed evidence of active exploitation.
What is the EPSS score for CVE-2026-0300?
32.1% - meaning FIRST.org's EPSS model estimates a 32.1% probability this vulnerability will be exploited in the wild within 30 days (98% percentile among all scored CVEs).
What type of vulnerability is CVE-2026-0300?
CVE-2026-0300 is classified under CWE-787 (CWE-787: Out-of-bounds Write).
Cross-checked against
Impactr finds and proves whether CVE-2026-0300 - or flaws like it - are actually reachable in your own web apps and APIs, with a reproducible exploit as evidence.
Join the waitlist