Critical Known exploited (KEV) CVE-2026-0300

Out-of-bounds write in Palo Alto PAN-OS (CVE-2026-0300) — unauthenticated root code execution on the firewall

Palo Alto Networks PAN-OS Added to KEV May 6, 2026 Federal remediation due 2026-05-09

PAN-OS, the OS for Palo Alto Networks firewalls, has an out-of-bounds write flaw in the User-ID Authentication Portal (Captive Portal). A remote, unauthenticated attacker can execute code as root on PA-Series and VM-Series firewalls via crafted packets. CISA listed it as known-exploited (KEV) (CVSS 9.8 Critical, per NVD).

Key facts

  • CVE IDCVE-2026-0300
  • CVSS base score9.8 CRITICAL
  • CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Affected (vendor / product)Palo Alto Networks PAN-OS
  • CWECWE-787
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2026-05-09 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • Out-of-bounds write in the User-ID Authentication Portal (Captive Portal) of PAN-OS
  • A remote, unauthenticated attacker can run code as root on PA/VM-Series via crafted packets
  • Listed in CISA KEV = exploitation confirmed; NVD base score near-maximum 9.8 Critical
  • Taking over the firewall itself turns the linchpin of defense into the attacker's base
  • Response: apply Palo Alto's fix; review Captive Portal exposure and logs (federal deadline May 9, 2026)
  • Take the firewall itself and the linchpin of the defence becomes the attacker foothold.

1PAN-OS at the network boundary

CVE-2026-0300 is an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) of Palo Alto Networks PAN-OS. PAN-OS is the OS that runs Palo Alto's boundary firewalls (PA-Series and VM-Series).

2What a crafted packet can do

Per CISA, an unauthenticated attacker can achieve root-privileged remote code execution (RCE) on the firewall by sending specially crafted packets. An out-of-bounds write is a flaw where a program writes beyond its allocated memory region, which can lead to arbitrary code execution through memory corruption. It is worse that the target is an "authentication portal" — an entry point readily reachable from outside.

3Why edge devices are dangerous

This class of device is dangerous because (1) it sits at the internet/internal boundary and is reachable from outside, and (2) once the firewall itself is taken over, the linchpin of defense becomes the attacker's base. The flaw needs no authentication and has low complexity, with severe impact to confidentiality, integrity, and availability.

4The device that defends becomes the foothold

An edge-device vulnerability weighs heavily because what is lost is not only information. Take the firewall itself and the linchpin of the defence becomes the attacker's base.

  1. 1It is reachable from outsidePlaced at the boundary, it has to be visible from the internet
  2. 2The authentication portal is the entranceThe part users touch first becomes the destination for a crafted packet
  3. 3Code runs as rootMemory corruption from an out-of-bounds write yields control of the device
  4. 4The linchpin becomes the baseThe firewall itself is used as the attacker's foothold

No authentication, low complexity, and severe impact to confidentiality, integrity and availability alike — close to the worst combination available. In responding, identifying the affected PAN-OS versions matters alongside determining whether the User-ID authentication portal (Captive Portal) is enabled and exposed externally.

Why it matters

The firewall guarding the boundary can itself be taken to root without authentication. Organizations using Palo Alto at the boundary should inventory Captive Portal exposure, patch immediately, and review access logs. It reflects the reality of attacks aimed at the defense devices themselves.

FAQ

What is PAN-OS?
The OS that runs Palo Alto Networks firewalls (PA-Series and VM-Series). It sits at the network boundary, controlling traffic and handling authentication.
What is an out-of-bounds write?
A flaw where a program writes beyond its allocated memory region. Through memory corruption it can lead to arbitrary code execution — here, with the highest (root) privilege.
What should I do?
Check Palo Alto's official advisory for affected versions, review whether the User-ID Authentication Portal (Captive Portal) is enabled/exposed, and apply the fix or mitigation. Review access logs.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Palo Alto Networks#PAN-OS#Firewall#Out-of-bounds write#RCE
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.