Palo Alto Networks has revealed that malicious actors may have attempted to exploit a recently disclosed critical security vulnerability . Exploitation attempts may have begun as early as April 9, 2026. The vulnerability, tracked as CVE-2026-0300 (CVSS score: 9.3/8.7), is a buffer overflow vulnerability in the User-ID Authentication Portal service of Palo Alto Networks PAN-OS software . Successful exploitation could allow an unauthenticated attacker to execute arbitrary code with root privileges by sending specially crafted packets.

While fixes are expected to be released starting May 13, 2026, customers are urged to secure access to the PAN-OS by restricting access to trusted zones or disabling it completely (if possible).
See also: Ivanti EPMM: Hackers exploit RCE vulnerability
In an advisory issued Wednesday, the company said it is aware of limited exploitation of the vulnerability. The activity is being attributed to CL-STA-1132, a suspected threat group of unknown origin.
“The attacker behind this activity exploited CVE-2026-0300 to achieve unauthenticated remote code execution (RCE) in the PAN-OS software. After successful exploitation, the attacker was able to inject shellcode into an nginx worker process,” said .
The cybersecurity firm said it observed some unsuccessful attempts exploit since April 9, 2026, after which attackers were able to achieve remote code execution against the device and inject shellcode. Once initial access was gained, the malicious actors took steps to clean up crash kernel messages, delete entries and nginx crash records, and remove crash core dump files.
See also: Ollama vulnerability allows sensitive information to be leaked
PAN-OS vulnerability exploitation and subsequent malicious activity
Post-exploit activities included performing Active Directory (AD) enumeration and installing additional payloads such as EarthWorm and ReverseSocks5 against a second device, on April 29, 2026. Both tools have been previously used by various China-linked hacker groups.

“cyber-espionage threat actors sponsored have increasingly focused their efforts on edge-network technological assets, including firewalls, routers, IoT devices, hypervisors, and various VPN solutions, which provide highly privileged access while often lacking the robust logging and security agents found on typical endpoints,” Unit 42 said.
See also: Gemini CLI: Critical vulnerability allowed supply chain attacks
This case highlights how quickly critical vulnerabilities in critical network infrastructure can be exploited, even before patches are fully released. The potential targeted exploitation of PAN-OS shows that systems such as firewalls remain a particularly attractive target for attackers, as they offer access to entire corporate environments when compromised.

At the same time, this development confirms the increasing sophistication of modern attacks, which use detection evasion techniques, open source tools and persistence in the target environment for extended periods. In this context, prompt application of updates, strict access restriction and enhanced network monitoring are critical measures to reduce risk and limit potential impacts.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
