PT-2026-37340 · Palo Alto Networks · Pan-Os+2
CVE-2026-0300
·
Published
2026-05-06
·
Updated
2026-07-13
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Palo Alto Networks PAN-OS versions 10.2.0 through 10.2.4
Description
A buffer overflow (an out-of-bounds write) exists in the User-ID Authentication Portal (also known as Captive Portal) service. This flaw allows an unauthenticated remote attacker to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls by sending specially crafted packets. The vulnerability is actively exploited in the wild by a suspected state-sponsored threat cluster tracked as CL-STA-1132. Attackers have been observed injecting shellcode into the
worker nginx process, deploying tunneling tools such as EarthWorm and ReverseSocks5 to maintain persistence, and performing SAML floods to move to secondary devices. Approximately 5,800 VM-Series firewalls have been identified as exposed globally, with significant concentrations in Asia and North America.Recommendations
Update PAN-OS to the fixed version released on May 13.
As a temporary mitigation, disable the User-ID Authentication Portal service or restrict its access to only trusted internal IP addresses.
For users with Advanced Threat Prevention subscriptions, enable specific threat identifiers to block exploitation attempts.
Exploit
Fix
DoS
LPE
RCE
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pa-Series
Pan-Os
Vm Series