CVE-2026-0300

Palo Alto Networks PAN-OS: Out-of-bounds Write

As of , CVE-2026-0300 in Palo Alto Networks PAN-OS is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch soon.

Exploited
Yes: CISA listed it on 6 May 2026
US federal deadline
9 May 20263 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
EPSS score
0.32Higher than 98% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
Public exploit
None foundNeither Metasploit nor Exploit-DB lists one.
Fix
Vendor advice: security.paloaltonetworks.comLinks below, from CISA's entry.

What CISA says to do

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: - Restrict User-ID Authentication Portal access to only trusted zones. - Disable User-ID Authentication Portal if not required. 5/13/2026: Palo Alto has released a variety of patches. If these are relevant to your environment, please apply the designated patch.

CISA's required action

What the flaw is

Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.

CISA's description

A buffer overflow vulnerability in the User-IDTM Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-IDTM Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.

The CVE record's description, from palo_alto

CVE published
6 May 2026
Assigned by
palo_alto
CVSS
9.3 Critical (CVSS 4.0, from the CNA)
CWE-787
Out-of-bounds Write
CISA SSVC, exploitation
active
CISA SSVC, automatable
yes
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. The US federal deadline to fix it.
  4. CISA changed its entry. Edited: required action.

PAN-OS: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2026-0257Authentication BypassPalo Alto Networks PAN-OSPatch nowRansomware use, listed within a year0.97
CVE-2017-15944Remote Code ExecutionPalo Alto Networks PAN-OSPatch this weekMetasploit module; EPSS 0.98; verified Exploit-DB entry0.98
CVE-2024-0012Management Interface Authentication BypassPalo Alto Networks PAN-OSPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
CVE-2024-9474Management Interface OS Command InjectionPalo Alto Networks PAN-OSPatch this weekRansomware use; Metasploit module; EPSS 0.950.95
CVE-2024-3400Command InjectionPalo Alto Networks PAN-OSPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
CVE-2025-0108Authentication BypassPalo Alto Networks PAN-OSPatch this weekEPSS 0.980.98
CVE-2019-1579Remote Code ExecutionPalo Alto Networks PAN-OSPatch this weekRansomware use0.46
CVE-2020-2021Authentication BypassPalo Alto Networks PAN-OSPatch this weekRansomware use0.04
CVE-2024-3393Malicious DNS PacketPalo Alto Networks PAN-OSPatch soon0.29
CVE-2022-0028Reflected Amplification Denial-of-ServicePalo Alto Networks PAN-OSPatch soon0.03

All 12 entries for PAN-OS

Read further