PT-2026-37340 · Palo Alto Networks · Pan-Os+2

CVE-2026-0300

·

Published

2026-05-06

·

Updated

2026-07-13

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Palo Alto Networks PAN-OS versions 10.2.0 through 10.2.4
Description A buffer overflow (an out-of-bounds write) exists in the User-ID Authentication Portal (also known as Captive Portal) service. This flaw allows an unauthenticated remote attacker to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls by sending specially crafted packets. The vulnerability is actively exploited in the wild by a suspected state-sponsored threat cluster tracked as CL-STA-1132. Attackers have been observed injecting shellcode into the worker nginx process, deploying tunneling tools such as EarthWorm and ReverseSocks5 to maintain persistence, and performing SAML floods to move to secondary devices. Approximately 5,800 VM-Series firewalls have been identified as exposed globally, with significant concentrations in Asia and North America.
Recommendations Update PAN-OS to the fixed version released on May 13. As a temporary mitigation, disable the User-ID Authentication Portal service or restrict its access to only trusted internal IP addresses. For users with Advanced Threat Prevention subscriptions, enable specific threat identifiers to block exploitation attempts.

Exploit

Fix

DoS

LPE

RCE

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06322
CVE-2026-0300

Affected Products

Pa-Series
Pan-Os
Vm Series