Exploited in the wild PAN-OS CL-STA-1132 rce PA-Series firewalls Palo Alto Networks
Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution
Executive Summary
On May 6, 2026, Palo Alto Networks released a CVE-2026-0300">security advisory for CVE-2026-0300, identifying a buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software. Vulnerable systems allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.…