U.S. CISA adds a flaw in Palo Alto Networks PAN-OS to its Known Exploited Vulnerabilities catalog


U.S. CISA adds a flaw in Palo Alto Networks PAN-OS to its Known Exploited Vulnerabilities catalog

Pierluigi Paganini
May 07, 2026

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Palo Alto Networks PAN-OS to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in the Palo Alto Networks PAN-OS, tracked as CVE-2026-0300 (CVSS score of 9.3), to its Known Exploited Vulnerabilities (KEV) catalog.

The flaw is a buffer overflow that allows unauthenticated remote code execution, especially when the User-ID portal is exposed to the internet.

“A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.” reads the advisory published by Palo Alto Networks. “The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines by restricting access to only trusted internal IP addresses.”

This week, Palo Alto Networks has warned that the critical PAN-OS vulnerability CVE-2026-0300 is actively exploited in the wild.

Below is the list of impacted products:

Versions Affected Unaffected
Cloud NGFW None All
PAN-OS 12.1 < 12.1.4-h5
< 12.1.7
>= 12.1.4-h5 (ETA: 05/13)
>= 12.1.7 (ETA: 05/28)
PAN-OS 11.2 < 11.2.4-h17
< 11.2.7-h13
< 11.2.10-h6
< 11.2.12
>= 11.2.4-h17 (ETA: 05/28)
>= 11.2.7-h13 (ETA: 05/13)
>= 11.2.10-h6 (ETA: 05/13)
>= 11.2.12 (ETA: 05/28)
PAN-OS 11.1 < 11.1.4-h33
< 11.1.6-h32
< 11.1.7-h6
< 11.1.10-h25
< 11.1.13-h5
< 11.1.15
>= 11.1.4-h33 (ETA: 05/13)
>= 11.1.6-h32 (ETA: 05/13)
>= 11.1.7-h6 (ETA: 05/28)
>= 11.1.10-h25 (ETA: 05/13)
>= 11.1.13-h5 (ETA: 05/13)
>= 11.1.15 (ETA: 05/28)
PAN-OS 10.2 < 10.2.7-h34
< 10.2.10-h36
< 10.2.13-h21
< 10.2.16-h7
< 10.2.18-h6
>= 10.2.7-h34 (ETA: 05/28)
>= 10.2.10-h36 (ETA: 05/13)
>= 10.2.13-h21 (ETA: 05/28)
>= 10.2.16-h7 (ETA: 05/28)
>= 10.2.18-h6 (ETA: 05/13)
Prisma Access None All

The cybersecurity vendor states that the issue doesn’t impact Prisma Access, Cloud NGFW and Panorama appliances.

Palo Alto Networks says the flaw is being exploited in a limited way, mainly against systems where the User-ID Authentication Portal is exposed to the public internet.

The flaw remains unpatched, with fixes expected from May 13, 2026. It affects PA-Series and VM-Series firewalls using the User-ID Authentication Portal. Palo Alto Networks notes risk is much lower for organizations that follow best practices, like limiting access to trusted internal networks only.

“Limited exploitation has been observed targeting Palo Alto Networks User-ID™ Authentication Portals that are exposed to untrusted IP addresses and/or the public internet.” concludes the advisory. “Customers following standard security best practices, such as restricting sensitive portals to trusted internal networks are at a greatly reduced risk.”

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerability by May 9, 2026.

Pierluigi Paganini

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

(SecurityAffairs – hacking, US CISA Known Exploited Vulnerabilities catalog)







Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


With the start of April, Netflix is welcoming entertaining movies that will be available to stream for the foreseeable future. One of the new movies I’m ready to watch is Thrash, a new shark movie where the Jaws-like creatures wreak havoc on a coastal town during a hurricane. It might only be spring, but I’ll watch this type of survival thriller any time of the year.

Speaking of thrillers, there are several prominent movies featured on the genre page. My top pick for thrillers this week is a gritty punk-rock film, now streaming on Netflix in the U.S. The other two thrillers we want to spotlight are a twisty crime tale from the 1990s and an allegorical dystopian mystery set in prison.

3

The Platform

Maybe don’t watch on a full stomach

Read what I wrote under the title again. The Platform is not for viewers with queasy stomachs. I have a strong stomach, and yet there are several moments when certain prisoners chow down where I wanted to look away. Between that and the violence, watching before dinner might be the move.

In a dystopian future, there is a prison called the Vertical Self-Management Center. Two prisoners are stationed on each floor, and there is a giant hole in the center. Every day, a platform filled with food lowers to the floor. Prisoners can have as much food as they want when the platform is on their level. However, they can no longer eat when the platform lowers to the next floor. The higher you are in the building, the more food you’ll have at your disposal. The lower floors are left to eat the scraps.

The Platform has much to say about social inequality and greed. I did not expect the Spanish thriller to be as gory as it was. This movie reflects how society treats the rich and the poor, so I should have expected a few uprisings. Overall, it’s a surprisingly effective thriller.​​​​​​​

2

Wild Things

A steamy thriller from the 1990s

The following phrase is meant as a compliment: Wild Things is sexy trash. It is unapologetically lustful. It’s like playing Mad Libs with an erotic thriller. Plus, its attractive cast—Matt Dillon, Neve Campbell, Denise Richards, Daphne Rubin-Vega, and Kevin Bacon—adds to the appeal.

In Miami, high school counselor Sam Lombardo (Dillon) is accused of raping popular student Kelly Van Ryan (Richards) and outcast Suzie Toller (Campbell). Sam then hires sleazy lawyer Kenneth Bowden (Murray) to defend him at trial. As the case progresses, Detective Duquette (Bacon) remains suspicious of the girls’ motives and questions whether Sam is innocent.

I’m being intentionally vague in my synopsis because of the significant twists this movie takes. Even if you guess one of the twists, more will follow. It approaches parody with how ridiculous it is, but I’m a sucker for this movie. It’s a soap opera with scandal, murder, and sexual longing. Wild Things is a scripted version of your favorite reality TV show.​​​​​​​

1

Caught Stealing

Austin Butler races around New York City

Austin Butler has the “it factor.” Ever since Elvis, Hollywood has been pushing Butler as one of its future stars. The 34-year-old has the looks and skills of an A-list talent. He has good taste, as evidenced by the directors he works with, a list that includes Quentin Tarantino, Jeff Nichols, Denis Villeneuve, Ari Aster, and Darren Aronofsky.

Butler headlined Aronofsky’s 2025 crime thriller Caught Stealing. In the late 1990s, Hank (Butler) is a bartender living in New York City. Hank had aspirations of playing in the MLB, but a car accident derailed his opportunity. One day, Hank’s neighbor Russ (Matt Smith) asks him to look after his cat. That small task somehow leads to Hank going on the run from Russian mobsters.

Butler is the perfect actor for this star-making performance that would have taken him to new heights had it come out in the 1990s. Caught Stealing was considered a box office flop—$32 million on an estimated budget of $40 million. I don’t necessarily blame Butler for the poor box office. I think the August 29 release date played a role in its poor performance. Butler’s inclusion in a project might not lead to significant financial gains. However, I appreciate that he made a grimy mid-budget crime thriller that has seemingly disappeared from today’s movie landscape. If Butler’s down to make more crime capers with breakneck action and frenetic pacing, sign me up.


More movies and shows to stream on Netflix

Netflix users in the United States, you got it made. There are thousands of movies and TV shows to stream with the push of a button. For some family-friendly content with Dwayne Johnson and Jack Black, Jumanji: Welcome to the Jungle is now on Netflix. If you want something more adult-focused, give some serials like Black Mirror a chance.

Subscription with ads

Yes, $8/month

Simultaneous streams

Two or four




Source link