Article

    Cyber News / Article / Critical Buffer Overflow Vulnerability in PAN-OS Exploited in-the-Wild

    Critical Buffer Overflow Vulnerability in PAN-OS Exploited in-the-Wild
    Me
    Merav Bar-2026-05-06

    Critical Buffer Overflow Vulnerability in PAN-OS Exploited in-the-Wild

    Detect and mitigate CVE-2026-0300, a critical vulnerability in Palo Alto Networks PAN-OS User-ID Authentication Portal that allows unauthenticated attackers to achieve remote code execution (RCE) with root privileges.

    A critical vulnerability (CVE-2026-0300) has been identified in Palo Alto Networks PAN-OS that allows unauthenticated attackers to achieve remote code execution (RCE) with root privileges. The issue affects the User-ID Authentication Portal (Captive Portal) and is actively exploited in limited cases, particularly when exposed to untrusted networks or the public internet.

    The vulnerability is a buffer overflow in the User-ID Authentication Portal service. By sending specially crafted network packets, an unauthenticated attacker can trigger an out-of-bounds write condition, ultimately leading to arbitrary code execution with root privileges on affected devices. The attack requires no authentication, user interaction, or special conditions beyond network access.

    Exploitation risk is significantly higher when the Authentication Portal is exposed externally. The service is typically used for user identification workflows (e.g., captive portals), but when accessible from the Internet or untrusted networks, it becomes an entry point for remote attackers. The vulnerability has a CVSS score of 9.3, and Palo Alto has stated that it has already seen limited in-the-wild exploitation targeting exposed instances.

    Limited details have been published as of May 6, 2026. Wiz will continue to update this blogpost when additional details will come to life.

    While Wiz data indicates that 7% of environments have publicly exposed PAN-OS instances, Palo Alto Networks specifies that the vulnerability is within the User-ID Authentication Portal. Since this portal utilizes ports 6081 and 6082, the exposure of these specific ports is the primary metric for exploitability. Currently, Shodan identifies 67 exposed PAN-OS servers on port 6081, with none detected on port 6082.

    Apply patches immediately once fixed versions become available for your PAN-OS release branch

    Restrict access to the User-ID Authentication Portal to trusted internal IP addresses only

    Disable the Authentication Portal if it is not required

    Avoid exposing the portal to the internet or untrusted networks

    Wiz customers can use the pre-built queries and advisory in theWiz Threat Intel Centerto search for relevant instances in their environment.

    Palo Alto advisory

    Streamline pen-testing by unifying findings from bug bounties, manual audits, and Wiz Red Agent into a single, context-rich view.

    Get actionable best practices to shrink your attack surface, protect execution environments, control package ingestion, and catch compromises early.

    Following your foundation, operationalize Wiz across development, detection and response, and program maturity so your security program never stops getting stronger.

    Get a personalized demo

    ©2026Wiz, Inc.

    StatusPrivacy PolicyTerms of UseModern Slavery StatementCookie Settings

    Original source