


Perceptive Security
SOC/SIEM Consultancy

Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unau…
Published:
6 May 2026 at 00:00:00
Alert date:
6 May 2026 at 19:01:25
Source:
cisa.gov
Network Infrastructure, Zero-Day Vulnerabilities
Palo Alto Networks PAN-OS contains a critical out-of-bounds write vulnerability in the User-ID Authentication Portal (Captive Portal) service. The vulnerability affects PA-Series and VM-Series firewalls and allows unauthenticated attackers to execute arbitrary code with root privileges. Attackers can exploit this vulnerability by sending specially crafted packets to the affected systems. This represents a critical security risk as it provides complete system compromise without authentication requirements. The vulnerability is tracked as CVE-2026-0300 and has been assigned a high criticality rating.
Technical details
Mitigation steps:
Affected products:
Palo Alto Networks PAN-OS
PA-Series Firewalls
VM-Series Firewalls
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
