2026-006: Critical Vulnerability in PAN-OS

Imported from official source

Advisory

Cybersecurity Classified by Officially

  • 06/05/2026 --- v1.0 -- Initial publication
  • On 6 May 2026, Palo Alto published a security advisory addressing a critical vulnerability affecting PAN-OS [1]. This vulnerability allows an unauthenticated attacker to execute arbitrary code with root privileges.

    Palo Alto observed limited exploitation of this vulnerability. It is strongly recommended updating affected appliances as soon as patches will be available, and to apply workarounds and mitigation in the meantime.

    The vulnerability CVE-2026-0300, with the CVSS score of 9.3, is a buffer overflow in the User-ID Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software. [1]

    An unauthenticated attacker could execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. [1]

    This issue is applicable only to PA-Series and VM-Series firewalls that are configured to use User-ID Authentication Portal.

    The following PAN-OS versions are affected:

    Additional information is available in the vendor’s advisory [1].

    The patches are not available at the time of writing, but are scheduled to be released in the near future. It is recommended updating affected devices as soon as the patches will be released.

    It is possible to mitigate the risk of this flaw by taking either of the following actions [1]:

  • Restrict User-ID Authentication Portal access to only trusted zones.
  • Disable User-ID Authentication Portal if not required.
  • This is an extract. The publication continues at the source.

    Source: CERT-EU.

    Read the original at the source: https://cert.europa.eu/publications/security-advisories/2026-006/

    Officially imported this from CERT-EU’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    CERT-EU — imported from official source
    Official source
    https://www.cert.europa.eu/publications/security-advisories-rss RSS
    Imported
    September 15, 2026 20:57
    Versions
    1 recorded
    Identity
    security-advisories-10943

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.