LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-0300: Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 6, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 9, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-0300 to its Known Exploited Vulnerabilities catalog on May 6, 2026, with a federal patch deadline of May 9, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute…

This vulnerability is an out-of-bounds write in the User-ID Authentication Portal service of Palo Alto Networks PAN-OS. An unauthenticated attacker can send specially crafted packets to execute arbitrary code with root privileges on affected PA-Series and VM-Series firewalls. It matters because successful exploitation grants an attacker full control of the firewall, which typically sits at a network perimeter or between security zones.

How it works

The weakness is classified as CWE-787, an out-of-bounds write. The flaw exists in the User-ID Authentication Portal, also known as the Captive Portal service.

An attacker abuses the issue by sending specially crafted packets to the service. This can result in arbitrary code execution with root privileges on the firewall.

Am I affected? How to find it in your systems

The vulnerability affects Palo Alto Networks PAN-OS on PA-Series and VM-Series firewalls where the User-ID Authentication Portal service is present.

How to remediate

Apply the vendor patches released by Palo Alto Networks. Follow the designated patch instructions for your specific PAN-OS deployments.

If you can't patch immediately

Until a patch can be applied, implement the documented workarounds.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to breaches that expose credentials or network access. You can run a free exposure scan of your email addresses to check against known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedPalo Alto Networks · PAN-OS
WeaknessCWE-787
Added to CISA KEVMay 6, 2026
Federal patch deadlineMay 9, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities