VulnerabilitiesMay 7, 2026
New threat brief: CVE-2026-0300, a buffer overflow vulnerability in the PAN-OS User-ID Authentica...
CVE-2026-0300 buffer overflow in PAN-OS User-ID portal enables unauthenticated RCE.
Summary
Unit 42 has identified CVE-2026-0300, a buffer overflow vulnerability in the Palo Alto Networks PAN-OS User-ID Authentication Portal that allows unauthenticated remote code execution. Limited exploitation has been observed in the wild. Palo Alto Networks has released mitigation guidance and patches to address the flaw.
Indicators of Compromise
- cve — CVE-2026-0300
Entities
Palo Alto Networks (vendor)PAN-OS (product)Unit 42 (threat_actor)