Pandorex
Security

Palo Alto Zero-Day Hits Firewalls: Why CVE-2026-0300 Belongs at the Top of the Priority List

Published Pandorex Redaktion·4 min read
—

Palo Alto Networks has disclosed CVE-2026-0300, a critical buffer overflow in the PAN-OS User-ID Authentication Portal, also known as Captive Portal. The issue affects PA-Series and VM-Series firewall appliances when the portal is enabled and reachable from untrusted networks or the public internet. According to Palo Alto Networks and Rapid7, limited exploitation has already been observed in the wild.

What Makes This Different

This is not a vulnerability somewhere behind the firewall. It is a vulnerability in the firewall itself — and in a feature that can sit directly on the edge of the network. Rapid7 describes the issue as unauthenticated remote code execution with root privileges via specially crafted packets. No user interaction is required.

The affected component is not enabled by default in every environment, which limits the blast radius. But for organisations that use Captive Portal and expose it beyond trusted internal zones, the risk profile is severe. Palo Alto Networks has assigned a CVSSv4 score of 9.3, and CISA added the CVE to its Known Exploited Vulnerabilities catalog on May 6.

Patch Timing Creates an Operational Gap

The first fixed versions are expected from May 13, with additional branches following later in May. That creates a dangerous gap: defenders know the vulnerability is being exploited, but not every affected system can be patched immediately. In that window, mitigation quality matters more than normal change-management comfort.

  • Check exposure: Identify whether User-ID Authentication Portal is enabled and reachable from untrusted zones or the internet.
  • Restrict access: Limit the portal to trusted internal zones only.
  • Disable if unused: If Captive Portal is not operationally required, turn it off until fixed builds are available.
  • Prepare patch windows: Track the vendor release schedule for each PAN-OS branch and patch as soon as the relevant fixed version exists.
  • Hunt for compromise: Review firewall logs, authentication portal access patterns, unexpected tunnels, and Active Directory enumeration activity.

Pandorex View

CVE-2026-0300 is a reminder that perimeter devices are no longer just defensive infrastructure. They are high-value Linux-based systems with privileged network position, identity context, and a history of being targeted by state-aligned actors. A vulnerable firewall is not a wall with a crack — it can become the attacker’s first foothold.

The practical lesson is simple: edge services deserve internet-speed response. If a firewall feature is not required, it should not be exposed. If it is required, it needs the same monitoring, segmentation, and emergency-change path as any other internet-facing critical service.

Sources: Palo Alto Networks security advisory for CVE-2026-0300, Rapid7 analysis (06./07.05.2026), BleepingComputer (06.05.2026), CISA KEV catalog.

Comments

Sign in to write a comment.

Swipe up
Next Article

Edge AI in the Browser Becomes the New Security Boundary

Security