Palo Alto warns of critical firewall flaws and tells users that a patch is on the way


  • A critical buffer overflow vulnerability (CVE-2026-0300) in the PAN-OS User-ID Authentication Portal is under limited exploitation
  • The flaw allows unauthorized code execution with root privileges on vulnerable firewalls
  • Palo Alto advised restricting portals to trusted networks; corrections are due on 13 May 2026

The PAN-OS User-ID Authentication Portal, a feature of Palo Alto Networks firewalls that identifies and authenticates users on a network, contains a critical severity zero-day vulnerability that is being exploited in limited attacks, the company has warned.

The flaw is described as a buffer overflow vulnerability that allows unauthorized threat actors to run arbitrary code with root privileges on PA-series and VM-series firewalls via specially crafted packets.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top