AI Stories on SHORT INFO are generated & curated with AI
9 linked sources 18 Aug, 19:37

Palo Alto Networks CVE-2026-0300 PAN-OS captive portal zero-day under active state-sponsored exploitation - root RCE CVSS 9.3 - second patch wave May 28

Anyone running a Palo Alto firewall with the User-ID portal exposed online should patch right now. CVE-2026-0300 lets attackers gain root with no login. A state-linked group is already exploiting it. Second patch wave May 28. Palo Alto Networks $PANW.

Palo Alto Networks disclosed CVE-2026-0300 May 6 after Unit 42 detected exploitation in the wild. Buffer overflow in the User-ID Authentication Portal lets unauthenticated attackers gain root on PA-Series and VM-Series firewalls. CVSS 9.3. Unit 42 attributes activity to cluster CL-STA-1132, likely state-sponsored. First patch wave shipped May 13, second wave covering older releases due May 28. Palo Alto Networks $PANW. Sources: Unit 42, Palo Alto Networks Security Advisory, NVD, SecurityWeek, Help Net Security, Hacker News, Rapid7, SC Media.

#cyber
Published on
TikTokYouTubeBlueskyThreadsFacebookInstagramX