CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2026-0300

CVSS 9.3v4.0pub. 2026-05-06upd. 2026-05-12

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.

🤖 AI Analysis
How it works

An attacker sends specially crafted network packets to the User-ID Authentication Portal (Captive Portal) service running in PAN-OS. Due to a CWE-787 error (out-of-bounds write), a buffer overflow occurs in the memory of the portal-handling process. This allows the attacker to take control of the program's execution flow and execute arbitrary code with root privileges without prior authentication. The risk is significantly reduced if access to the Captive Portal is restricted exclusively to trusted internal IP addresses in accordance with the vendor's guidelines.

Impact

An attacker gains full control of the device with root privileges, enabling arbitrary system command execution, backdoor installation, theft of configuration and credentials, and use of the device as an entry point to the internal network.

Mitigation & patch

Apply patches available from the vendor according to the references (https://security.paloaltonetworks.com/CVE-2026-0300). Until the patch is implemented, as a workaround, immediately restrict access to the User-ID Authentication Portal (Captive Portal) service exclusively to trusted internal IP addresses in accordance with the vendor's guidelines.

Who is affected

Palo Alto Networks PA series firewalls (PA-440, PA-1410, PA-5560, PA-5580, PA-7500) and VM-Series running PAN-OS software with the User-ID Authentication Portal (Captive Portal) service enabled. Prisma Access, Cloud NGFW, and Panorama devices are not vulnerable.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Red
  • Palo Alto Networks Pa 1410

    HW
    Paloaltonetworks
    all versions
  • Palo Alto Networks Pa 1420

    HW
    Paloaltonetworks
    all versions
  • Palo Alto Networks Pa 3410

    HW
    Paloaltonetworks
    all versions
  • Palo Alto Networks Pa 3420

    HW
    Paloaltonetworks
    all versions
  • Palo Alto Networks Pa 3430

    HW
    Paloaltonetworks
    all versions
  • Palo Alto Networks Pa 3440

    HW
    Paloaltonetworks
    all versions
  • Palo Alto Networks Pa 410

    HW
    Paloaltonetworks
    all versions
  • Palo Alto Networks Pa 410r

    HW
    Paloaltonetworks
    all versions
  • Palo Alto Networks Pa 410r 5g

    HW
    Paloaltonetworks
    all versions
  • Palo Alto Networks Pa 415

    HW
    Paloaltonetworks
    all versions
  • Palo Alto Networks Pa 415 5g

    HW
    Paloaltonetworks
    all versions
  • Palo Alto Networks Pa 440

    HW
    Paloaltonetworks
    all versions
  • Palo Alto Networks Pa 445

    HW
    Paloaltonetworks
    all versions
  • Palo Alto Networks Pa 450

    HW
    Paloaltonetworks
    all versions
  • Palo Alto Networks Pa 450r

    HW
    Paloaltonetworks
    all versions
  • Palo Alto Networks Pa 450r 5g

    HW
    Paloaltonetworks
    all versions
  • Palo Alto Networks Pa 455

    HW
    Paloaltonetworks
    all versions
  • Palo Alto Networks Pa 455 5g

    HW
    Paloaltonetworks
    all versions
  • Palo Alto Networks Pa 455r 5g

    HW
    Paloaltonetworks
    all versions
  • Palo Alto Networks Pa 460

    HW
    Paloaltonetworks
    all versions
  • Palo Alto Networks Pa 501

    HW
    Paloaltonetworks
    all versions
  • Palo Alto Networks Pa 505

    HW
    Paloaltonetworks
    all versions
  • Palo Alto Networks Pa 510

    HW
    Paloaltonetworks
    all versions
  • Palo Alto Networks Pa 520

    HW
    Paloaltonetworks
    all versions
  • Palo Alto Networks Pa 540

    HW
    Paloaltonetworks
    all versions
  • Palo Alto Networks Pa 5410

    HW
    Paloaltonetworks
    all versions
  • Palo Alto Networks Pa 5420

    HW
    Paloaltonetworks
    all versions
  • Palo Alto Networks Pa 5430

    HW
    Paloaltonetworks
    all versions
  • Palo Alto Networks Pa 5440

    HW
    Paloaltonetworks
    all versions
  • Palo Alto Networks Pa 5445

    HW
    Paloaltonetworks
    all versions

CISA KEV — detailsi

Vendori
Palo Alto Networks
Producti
PAN-OS
Added to KEVi
May 6, 2026
Remediation deadline (US Federal)i
May 9, 2026(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: - Restrict User-ID Authentication Portal access to only trusted zones. - Disable User-ID Authentication Portal if not required. 5/13/2026: Palo Alto has released a variety of patches. If these are relevant to your environment, please apply the designated patch.

CISA descriptioni

Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 9 maja 2026
Tags
RCEAuth BypassMemoryFirewall
CWE
References

Related vulnerabilities

CVE-2026-24858CRITICAL9.8⚠ KEVPL ✓same product

Fortinet – Auth Bypass przez FortiCloud SSO w wielu produktach

CVE-2025-59718CRITICAL9.8⚠ KEVPL ✓same product

Fortinet FortiOS/FortiProxy/FortiSwitchManager — Auth Bypass przez SAML

CVE-2024-0012CRITICAL9.3⚠ KEVPL ✓same product

Authentication bypass w PAN-OS umożliwiający przejęcie uprawnień administratora

CVE-2024-3400CRITICAL10.0⚠ KEVPL ✓same product

RCE jako root w GlobalProtect — command injection w PAN-OS

CVE-2020-2021CRITICAL10.0⚠ KEVPL ✓same product

PAN-OS: Pomijanie uwierzytelnienia SAML przez brak weryfikacji podpisów