CVE-2026-0300 CRITICAL

Palo Alto Networks PAN-OS Vulnerability
Generated: 10 Oct 2026 20:40 • CVE Threat Intelligence

Description

Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.

9.8
CVSS CRITICAL

Details

Published
06 May 2026 00:00
Modified
N/A
Source
CIRCL
Vendor
Palo Alto Networks
Product
PAN-OS
Fix Version
Vendor Patch / Mitigation Available