HomeSecurityPalo Alto PAN-OS: Critical vulnerability under active exploitation

Palo Alto PAN-OS: Critical vulnerability actively exploited

Palo Alto Networks is warning about a critical vulnerability in PAN-OS, which is already being used in cyberattacks, allowing remote code execution. The vulnerability, CVE-2026-0300, concerns a buffer overflow in the User-ID Authentication Portal and poses a serious threat to corporate firewalls. The severity of the threat is enhanced by the fact that it allows unauthenticated access to critical security systems that protect entire corporate networks.

Palo Alto PAN-OS

According to Palo Alto Networks ' official announcement , the vulnerability allows unauthenticated attackers to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls . The exploitation is done via specially crafted packets. This means that attackers can gain complete control of the firewall without needing any credentials, turning an organization's primary security tool into an entry point for further attacks.

The vulnerability carries a CVSS score of 9.3 if the User-ID Authentication Portal is configured to allow access from the internet or any untrusted network. The severity is reduced to 8.7 if access to the portal is restricted to trusted internal IP addresses only.

The company confirmed that CVE-2026-0300 is under “limited exploitation,” with attackers primarily targeting instances where the User-ID Authentication Portal is accessible from the internet. Despite the “limited” nature of the attacks, the reality is that thousands of organizations worldwide have exposed PAN-OS management interfaces to the internet, creating a huge attack surface.

The history of vulnerabilities in Palo Alto products reveals a worrying pattern that highlights the systemic nature of the problem. In November 2024 , the company warned of a similar RCE vulnerability in PAN-OS , while other critical vulnerabilities were also identified, such as CVE-2024-5910 in Expedition and CVE-2024-9464 , which allows command injection. CVE-2024-9474 allows privilege escalation, while CVE-2025-0108 provides authentication bypass in the management web interface. This accumulation of vulnerabilities points to deeper architectural problems in the PAN-OS code .

See also: Palo Alto Networks: Critical vulnerability in PAN-OS

Palo Alto PAN-OS: Critical vulnerability actively exploited

The versions of PAN-OS affected by the new vulnerability are:

  • RAN-OS 12.1 – < 12.1.4-h5, < 12.1.7
  • RAN-OS 11.2 – < 11.2.4-h17, < 11.2.7-h13, < 11.2.10-h6, < 11.2.12
  • RAN-OS 11.1 – < 11.1.4-h33, < 11.1.6-h32, < 11.1.7-h6, < 11.1.10-h25, < 11.1.13-h5, < 11.1.15
  • RAN-OS 10.2 – < 10.2.7-h34, < 10.2.10-h36, < 10.2.13-h21, < 10.2.16-h7, < 10.2.18-h6

See also: Palo Alto Networks fixes vulnerability in PAN-OS Software

According to The Hacker News, the problem has not been fully fixed, with Palo Alto Networks planning to release updates starting May 13, 2026. This delay is particularly problematic given that firewalls are the first line of defense for most corporate networks.

The company said the vulnerability only applies to PA-Series and VM-Series firewalls configured to use the User-ID Authentication Portal.

Protection measures and security recommendations

Until patches are released, organizations should take immediate protective measures that include both technical and procedural changes. Palo Alto Networks recommends restricting access to the User-ID Authentication Portal to trusted zones or disabling it entirely (if possible). Additionally, administrators should implement network segmentation to isolate management interfaces from the main production network.

Organizations that follow standard security practices, such as restricting sensitive portals to trusted internal networks, are at significantly reduced risk. However, monitoring for signs of compromise remains critical and should include automated alerting for unusual activity.

See also: Vulnerability in Palo Alto Networks firewall allows DoS attacks

Palo Alto PAN-OS: Critical vulnerability actively exploited

Administrators should check firewall logs for unusual connection attempts from unrecognized IP addresses, monitor for unauthorized configuration changes, and look for web shell in the management interface directories. Particular attention should be paid to any new firewall rules that allow outbound connections to unrecognized destinations, as this may indicate the installation of backdoors.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Implementing multi-factor authentication for access to the management interface, implementing strong password policies, and immediately rotating administrator credentials are additional critical security enhancement measures.

The continued exploitation of vulnerabilities in Palo Alto products highlights the need for proactive security and prompt patching, as well as a fundamental rethinking of firewall management practices.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS