Palo Alto Networks製PAN-OSの脆弱性対策について(CVE-2026-0300)

Imported from official source

Announcement

Palo Alto Networks社より、PAN-OSに関する脆弱性が公表されました。

このPAN-OSのUser-ID Authentication Portalにおいて、バッファオーバーフローの脆弱性(CVE-2026-0300)が確認されています。
本脆弱性を悪用された場合、遠隔の第三者によって、当該製品で任意のコードを実行される可能性があります。

製品開発者は、本脆弱性を悪用する攻撃を確認していると公表しています。
今後被害が拡大する恐れがありますので、User-ID Authentication Portalの有効・無効の状態やアクセス制限の状況を確認のうえ、影響を受ける場合は、回避策について対応を検討してください。
また、製品開発者が公表・更新する情報を注視し、バージョンアップ等が利用可能となった際、迅速に適用できるよう対応ください。

注釈:製品開発者によると、Prisma Access、Cloud NGFW、および、Panorama appliancesは、この脆弱性の影響を受けないとのことです。

  • User-ID Authentication Portalへのアクセスを信頼できるアクセスのみに制限してください。
  • 必要でない場合は、User-ID Authentication Portalを無効にしてください。
  • This is an extract. The publication continues at the source.

    Read the original at the source: https://www.ipa.go.jp/security/security-alert/2026/alert20260508.html

    Officially imported this from Information-technology Promotion Agency (IPA)’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    Information-technology Promotion Agency (IPA) — imported from official source
    Official source
    https://www.ipa.go.jp/security/alert-rss.rdf RSS
    Imported
    October 03, 2026 20:39
    Versions
    1 recorded
    Identity
    https://www.ipa.go.jp/security/security-alert/2026/alert20260508.html

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.