Back to Feed
VulnerabilitiesMay 7, 2026

New threat brief: CVE-2026-0300, a buffer overflow vulnerability in the PAN-OS User-ID Authentica...

CVE-2026-0300 buffer overflow in PAN-OS User-ID portal enables unauthenticated RCE.

Summary

Unit 42 has identified CVE-2026-0300, a buffer overflow vulnerability in the Palo Alto Networks PAN-OS User-ID Authentication Portal that allows unauthenticated remote code execution. Limited exploitation has been observed in the wild. Palo Alto Networks has released mitigation guidance and patches to address the flaw.

Indicators of Compromise

  • cve — CVE-2026-0300

Entities

Palo Alto Networks (vendor)PAN-OS (product)Unit 42 (threat_actor)