INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Exploitation of PAN-OS Captive Portal Zero-Day
| 2026-05-07 00:00 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The threat landscape is evolving, with nation-state actors increasingly focusing on edge-network technological assets. Palo Alto Networks' Cortex Xpanse can identify exposed instances of the User-ID Authentication Portal potentially vulnerable to CVE-2026-0300, a buffer overflow vulnerability that allows an unauthenticated attacker to execute arbitrary code with root privileges. This vulnerability was identified by the company in response to a threat brief from Unit 42, which reported limited exploitation of the same vulnerability at this time.
Technical Mitigations AI-generated
• Restrict User-ID Authentication Portal access exclusively to trusted internal IP addresses and ensure the portal is not publicly reachable.
• Implement a firewall configuration that restricts network traffic to only necessary ports and protocols for PAN-OS software services.
• Use Palo Alto Networks Cortex Xpanse or Unit 42 Incident Response team engagement to identify exposed instances of the User-ID Authentication Portal.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
e11f69••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
Re•••••.tar
138.0.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
APT41APT41Volt TyphoonVolt Typhoon
CVE-2026-0300CVE-2026-0300
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
MIDDLE_EAST
MIDDLE_EAST
EUROPE
EUROPE
governmentgovernment
Incident Timeline
April 9, 2026
Threat actors exploited a zero-day vulnerability in the General Document Context of PAN-OS devices starting April 9, 2026.
April 29, 2026
Nation-state actors exploited a zero-day vulnerability in Palo Alto PAN-OS to gain unauthorized access and commandeer the targeted device.
May 6, 2026
Palo Alto Networks released a security advisory on May 6, 2026, identifying CVE-2026-0300 as the buffer overflow vulnerability in its User-ID Authentication Portal service.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-0300
Executive Summary
On May 6, 2026, Palo Alto Networks released a
security advisory for CVE-2026-0300
, identifying a buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software.
tactic
Buffer Overflow
Executive Summary
On May 6, 2026, Palo Alto Networks released a
security advisory for CVE-2026-0300
, identifying a buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software.
organisation
Palo Alto Networks
Executive Summary
On May 6, 2026, Palo Alto Networks released a
security advisory for CVE-2026-0300
, identifying a buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software.
organisation
User-ID
Executive Summary
On May 6, 2026, Palo Alto Networks released a
security advisory for CVE-2026-0300
, identifying a buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software.
2026/05/07
Nation-state threat actors exploited a buffer overflow vulnerability in the User-ID Authentication Portal service of Palo Alto Networks PAN-OS software to gain unauthorized access and execute arbitrary code with root privileges on PA-Series and VM-Series firewalls.
Click on any entity below to view its context and source!
organisation
IoT
Conclusion
Over the last five years, nation-state threat actors engaged in cyber espionage have increasingly focused their efforts on
edge-network
technological assets, including
firewalls
,
routers
,
IoT devices
,
hypervisors
and various
VPN solutions
, which provide high-privilege access while often lacking the robust logging and security agents found on standard endpoints.
organisation
PAN
Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution.
Nation-state actors exploit Palo Alto PAN-OS zero-day for weeks
Palo Alto says hackers exploited PAN-OS zero-day CVE-2026-0300 for weeks, gaining root access to exposed firewalls and hiding traces.
“A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.” reads the
advisory
published by Palo Alto Networks.
Shadowserver scans found more than
5,800 publicly exposed VM-Series firewalls
running PAN-OS as of Tuesday, yet it’s unknown how many of those instances have restricted authentication access to trusted internal IP addresses or disabled the feature altogether.
organisation
Palo Alto Networks
“A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.” reads the
advisory
published by Palo Alto Networks.
Palo Alto Networks did not say when or how it became aware of active exploitation, nor when the earliest known exploitation occurred.
organisation
User-ID
“A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.” reads the
advisory
published by Palo Alto Networks.
organisation
Shadowserver
Shadowserver scans found more than
5,800 publicly exposed VM-Series firewalls
running PAN-OS as of Tuesday, yet it’s unknown how many of those instances have restricted authentication access to trusted internal IP addresses or disabled the feature altogether.
organisation
Palo Alto Networks
Cortex Xpanse
Palo Alto Networks
Cortex Xpanse
can identify exposed instances of the User-ID Authentication Portal potentially vulnerable to CVE-2026-0300.
organisation
the User-ID Authentication Portal
Palo Alto Networks
Cortex Xpanse
can identify exposed instances of the User-ID Authentication Portal potentially vulnerable to CVE-2026-0300.
Palo Alto Networks says the flaw is being exploited in a limited way, mainly against systems where the User-ID Authentication Portal is exposed to the public internet.
organisation
Current Scope of the Attack Using CVE-2026-0300
Current Scope of the Attack Using CVE-2026-0300
We are aware of only limited exploitation of CVE-2026-0300 at this time.
organisation
Cortex Xpanse
Cortex Xpanse
Palo Alto Networks
Cortex Xpanse
can identify exposed instances of the User-ID Authentication Portal potentially vulnerable to CVE-2026-0300.
organisation
PAN-OS
The critical memory corruption vulnerability —
CVE-2026-0300
— affects the authentication portal of PAN-OS, and allows unauthenticated attackers to run code with root privileges on the vendor’s PA-Series and VM-Series firewalls, the company said.
Consequently, this campaign demonstrates that operational restraint—specifically the use of non-persistent access windows—is a primary factor in maintaining long-term residency on edge infrastructure.”
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, PAN-OS)
infrastructure
Windows
EarthWorm
Earthworm is an
open-source
network tunneling tool written in C that operates on Windows, Linux, macOS and ARM/MIPS-based platforms.
Consequently, this campaign demonstrates that operational restraint—specifically the use of non-persistent access windows—is a primary factor in maintaining long-term residency on edge infrastructure.
Indicators of Compromise
67.206.213[.]86
136.0.8[.]48
146.70.100[.]69 (C2 Staging)
149.104.66[.]84
hxxp[:]//146.70.100[.]69:8000/php_sess (EarthWorm Download)
hxxps[:]//github[.]com/Acebond/ReverseSocks5/releases/download/v2.2.0/ReverseSocks5-v2.2.0-linux-amd64.tar[.]gz (ReverseSocks5 Download)
e11f69b49b6f2e829454371c31ebf86893f82a042dae3f2faf63dcd84f97a584 (EarthWorm)
Safari/532.31 Mozilla/5.5 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
EarthWorm is an open-source tunneling tool written in C that works across Windows, Linux, macOS, and ARM/MIPS platforms.
Consequently, this campaign demonstrates that operational restraint—specifically the use of non-persistent access windows—is a primary factor in maintaining long-term residency on edge infrastructure.”
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, PAN-OS)
infrastructure
Linux
EarthWorm
Earthworm is an
open-source
network tunneling tool written in C that operates on Windows, Linux, macOS and ARM/MIPS-based platforms.
Indicators of Compromise
67.206.213[.]86
136.0.8[.]48
146.70.100[.]69 (C2 Staging)
149.104.66[.]84
hxxp[:]//146.70.100[.]69:8000/php_sess (EarthWorm Download)
hxxps[:]//github[.]com/Acebond/ReverseSocks5/releases/download/v2.2.0/ReverseSocks5-v2.2.0-linux-amd64.tar[.]gz (ReverseSocks5 Download)
e11f69b49b6f2e829454371c31ebf86893f82a042dae3f2faf63dcd84f97a584 (EarthWorm)
Safari/532.31 Mozilla/5.5 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
EarthWorm is an open-source tunneling tool written in C that works across Windows, Linux, macOS, and ARM/MIPS platforms.
infrastructure
Macos
EarthWorm
Earthworm is an
open-source
network tunneling tool written in C that operates on Windows, Linux, macOS and ARM/MIPS-based platforms.
EarthWorm is an open-source tunneling tool written in C that works across Windows, Linux, macOS, and ARM/MIPS platforms.
infrastructure
67.206.213
Indicators of Compromise
67.206.213[.]86
136.0.8[.]48
146.70.100[.]69 (C2 Staging)
149.104.66[.]84
hxxp[:]//146.70.100[.]69:8000/php_sess (EarthWorm Download)
hxxps[:]//github[.]com/Acebond/ReverseSocks5/releases/download/v2.2.0/ReverseSocks5-v2.2.0-linux-amd64.tar[.]gz (ReverseSocks5 Download)
e11f69b49b6f2e829454371c31ebf86893f82a042dae3f2faf63dcd84f97a584 (EarthWorm)
Safari/532.31 Mozilla/5.5 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
infrastructure
136.0.8
Indicators of Compromise
67.206.213[.]86
136.0.8[.]48
146.70.100[.]69 (C2 Staging)
149.104.66[.]84
hxxp[:]//146.70.100[.]69:8000/php_sess (EarthWorm Download)
hxxps[:]//github[.]com/Acebond/ReverseSocks5/releases/download/v2.2.0/ReverseSocks5-v2.2.0-linux-amd64.tar[.]gz (ReverseSocks5 Download)
e11f69b49b6f2e829454371c31ebf86893f82a042dae3f2faf63dcd84f97a584 (EarthWorm)
Safari/532.31 Mozilla/5.5 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
infrastructure
146.70.100
Indicators of Compromise
67.206.213[.]86
136.0.8[.]48
146.70.100[.]69 (C2 Staging)
149.104.66[.]84
hxxp[:]//146.70.100[.]69:8000/php_sess (EarthWorm Download)
hxxps[:]//github[.]com/Acebond/ReverseSocks5/releases/download/v2.2.0/ReverseSocks5-v2.2.0-linux-amd64.tar[.]gz (ReverseSocks5 Download)
e11f69b49b6f2e829454371c31ebf86893f82a042dae3f2faf63dcd84f97a584 (EarthWorm)
Safari/532.31 Mozilla/5.5 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
infrastructure
149.104.66
Indicators of Compromise
67.206.213[.]86
136.0.8[.]48
146.70.100[.]69 (C2 Staging)
149.104.66[.]84
hxxp[:]//146.70.100[.]69:8000/php_sess (EarthWorm Download)
hxxps[:]//github[.]com/Acebond/ReverseSocks5/releases/download/v2.2.0/ReverseSocks5-v2.2.0-linux-amd64.tar[.]gz (ReverseSocks5 Download)
e11f69b49b6f2e829454371c31ebf86893f82a042dae3f2faf63dcd84f97a584 (EarthWorm)
Safari/532.31 Mozilla/5.5 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
infrastructure
2.0
Indicators of Compromise
67.206.213[.]86
136.0.8[.]48
146.70.100[.]69 (C2 Staging)
149.104.66[.]84
hxxp[:]//146.70.100[.]69:8000/php_sess (EarthWorm Download)
hxxps[:]//github[.]com/Acebond/ReverseSocks5/releases/download/v2.2.0/ReverseSocks5-v2.2.0-linux-amd64.tar[.]gz (ReverseSocks5 Download)
e11f69b49b6f2e829454371c31ebf86893f82a042dae3f2faf63dcd84f97a584 (EarthWorm)
Safari/532.31 Mozilla/5.5 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
infrastructure
2.0-linux
Indicators of Compromise
67.206.213[.]86
136.0.8[.]48
146.70.100[.]69 (C2 Staging)
149.104.66[.]84
hxxp[:]//146.70.100[.]69:8000/php_sess (EarthWorm Download)
hxxps[:]//github[.]com/Acebond/ReverseSocks5/releases/download/v2.2.0/ReverseSocks5-v2.2.0-linux-amd64.tar[.]gz (ReverseSocks5 Download)
e11f69b49b6f2e829454371c31ebf86893f82a042dae3f2faf63dcd84f97a584 (EarthWorm)
Safari/532.31 Mozilla/5.5 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
infrastructure
532.31
Indicators of Compromise
67.206.213[.]86
136.0.8[.]48
146.70.100[.]69 (C2 Staging)
149.104.66[.]84
hxxp[:]//146.70.100[.]69:8000/php_sess (EarthWorm Download)
hxxps[:]//github[.]com/Acebond/ReverseSocks5/releases/download/v2.2.0/ReverseSocks5-v2.2.0-linux-amd64.tar[.]gz (ReverseSocks5 Download)
e11f69b49b6f2e829454371c31ebf86893f82a042dae3f2faf63dcd84f97a584 (EarthWorm)
Safari/532.31 Mozilla/5.5 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
infrastructure
5.5
Indicators of Compromise
67.206.213[.]86
136.0.8[.]48
146.70.100[.]69 (C2 Staging)
149.104.66[.]84
hxxp[:]//146.70.100[.]69:8000/php_sess (EarthWorm Download)
hxxps[:]//github[.]com/Acebond/ReverseSocks5/releases/download/v2.2.0/ReverseSocks5-v2.2.0-linux-amd64.tar[.]gz (ReverseSocks5 Download)
e11f69b49b6f2e829454371c31ebf86893f82a042dae3f2faf63dcd84f97a584 (EarthWorm)
Safari/532.31 Mozilla/5.5 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
infrastructure
10.0
Indicators of Compromise
67.206.213[.]86
136.0.8[.]48
146.70.100[.]69 (C2 Staging)
149.104.66[.]84
hxxp[:]//146.70.100[.]69:8000/php_sess (EarthWorm Download)
hxxps[:]//github[.]com/Acebond/ReverseSocks5/releases/download/v2.2.0/ReverseSocks5-v2.2.0-linux-amd64.tar[.]gz (ReverseSocks5 Download)
e11f69b49b6f2e829454371c31ebf86893f82a042dae3f2faf63dcd84f97a584 (EarthWorm)
Safari/532.31 Mozilla/5.5 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
infrastructure
537.36
Indicators of Compromise
67.206.213[.]86
136.0.8[.]48
146.70.100[.]69 (C2 Staging)
149.104.66[.]84
hxxp[:]//146.70.100[.]69:8000/php_sess (EarthWorm Download)
hxxps[:]//github[.]com/Acebond/ReverseSocks5/releases/download/v2.2.0/ReverseSocks5-v2.2.0-linux-amd64.tar[.]gz (ReverseSocks5 Download)
e11f69b49b6f2e829454371c31ebf86893f82a042dae3f2faf63dcd84f97a584 (EarthWorm)
Safari/532.31 Mozilla/5.5 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0 (Attacker User Agent String)
/var/tmp/linuxap, /var/tmp/linuxda, /var/tmp/linuxupdate (Tunneling Tools)
/tmp/.c
organisation
hxxps[:]//github[.]com/Acebond
Indicators of Compromise
67.206.213[.]86
136.0.8[.]48
146.70.100[.]69 (C2 Staging)
149.104.66[.]84
hxxp[:]//146.70.100[.]69:8000/php_sess (EarthWorm Download)
hxxps[:]//github[.]com/Acebond/ReverseSocks5/releases/download/v2.2.0/ReverseSocks5-v2.2.0-linux-amd64.tar[.]gz (ReverseSocks5 Download)
e11f69b49b6f2e829454371c31ebf86893f82a042dae3f2faf63dcd84f97a584 (EarthWorm)
Safari/532.31 Mozilla/5.5 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
organisation
Mozilla/5.5 (Windows NT 10.0
Indicators of Compromise
67.206.213[.]86
136.0.8[.]48
146.70.100[.]69 (C2 Staging)
149.104.66[.]84
hxxp[:]//146.70.100[.]69:8000/php_sess (EarthWorm Download)
hxxps[:]//github[.]com/Acebond/ReverseSocks5/releases/download/v2.2.0/ReverseSocks5-v2.2.0-linux-amd64.tar[.]gz (ReverseSocks5 Download)
e11f69b49b6f2e829454371c31ebf86893f82a042dae3f2faf63dcd84f97a584 (EarthWorm)
Safari/532.31 Mozilla/5.5 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
organisation
Win64
Indicators of Compromise
67.206.213[.]86
136.0.8[.]48
146.70.100[.]69 (C2 Staging)
149.104.66[.]84
hxxp[:]//146.70.100[.]69:8000/php_sess (EarthWorm Download)
hxxps[:]//github[.]com/Acebond/ReverseSocks5/releases/download/v2.2.0/ReverseSocks5-v2.2.0-linux-amd64.tar[.]gz (ReverseSocks5 Download)
e11f69b49b6f2e829454371c31ebf86893f82a042dae3f2faf63dcd84f97a584 (EarthWorm)
Safari/532.31 Mozilla/5.5 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
organisation
KHTML
Indicators of Compromise
67.206.213[.]86
136.0.8[.]48
146.70.100[.]69 (C2 Staging)
149.104.66[.]84
hxxp[:]//146.70.100[.]69:8000/php_sess (EarthWorm Download)
hxxps[:]//github[.]com/Acebond/ReverseSocks5/releases/download/v2.2.0/ReverseSocks5-v2.2.0-linux-amd64.tar[.]gz (ReverseSocks5 Download)
e11f69b49b6f2e829454371c31ebf86893f82a042dae3f2faf63dcd84f97a584 (EarthWorm)
Safari/532.31 Mozilla/5.5 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
organisation
SecurityAffairs
Consequently, this campaign demonstrates that operational restraint—specifically the use of non-persistent access windows—is a primary factor in maintaining long-term residency on edge infrastructure.”
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, PAN-OS)
organisation
Bridges
Bridges data between two separate listening ports to facilitate pivot management (T1090).
organisation
Encapsulates
Encapsulates traffic for protocols like RDP and SSH within SOCKS tunnels (T1572).
organisation
RDP
Encapsulates traffic for protocols like RDP and SSH within SOCKS tunnels (T1572).
Its features include forward and reverse SOCKS5 tunnels, port bridging, traffic forwarding, and multi-hop tunneling for protocols such as RDP and SSH.
organisation
SSH
Encapsulates traffic for protocols like RDP and SSH within SOCKS tunnels (T1572).
Its features include forward and reverse SOCKS5 tunnels, port bridging, traffic forwarding, and multi-hop tunneling for protocols such as RDP and SSH.
infrastructure
11.1
Decoder capabilities necessitate PAN-OS 11.1 or a later version for Threat ID support.
infrastructure
82.080.467
+82.080.467.8774
Advanced WildFire
The
Advanced WildFire
machine-learning models and analysis techniques have been reviewed and updated in light of indicators associated with this activity.
infrastructure
138.0.0
Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0 (Attacker User Agent String)
/var/tmp/linuxap, /var/tmp/linuxda, /var/tmp/linuxupdate (Tunneling Tools)
/tmp/.c
organisation
Attacker User
Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0 (Attacker User Agent String)
/var/tmp/linuxap, /var/tmp/linuxda, /var/tmp/linuxupdate (Tunneling Tools)
/tmp/.c
organisation
/tmp/.c
Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0 (Attacker User Agent String)
/var/tmp/linuxap, /var/tmp/linuxda, /var/tmp/linuxupdate (Tunneling Tools)
/tmp/.c
organisation
Prisma Access
While Prisma Access, Cloud NGFW and Panorama appliances remain unaffected by this vulnerability, the risk of unauthenticated RCE exploitation is significantly elevated when the User-ID Authentication Portal is exposed to the public internet or untrusted networks.
>= 11.1.7-h6 (ETA: 05/28)
>= 11.1.10-h25 (ETA: 05/13)
>= 11.1.13-h5 (ETA: 05/13)
>= 11.1.15 (ETA: 05/28)
PAN-OS 10.2
< 10.2.7-h34
< 10.2.10-h36
< 10.2.13-h21
< 10.2.16-h7
< 10.2.18-h6
>= 10.2.7-h34 (ETA: 05/28)
>= 10.2.10-h36 (ETA: 05/13)
>= 10.2.13-h21 (ETA: 05/28)
>= 10.2.16-h7 (ETA: 05/28)
>= 10.2.18-h6 (ETA: 05/13)
Prisma Access
None
All
The cybersecurity vendor states that the issue doesn’t impact Prisma Access, Cloud NGFW and Panorama appliances.
organisation
Panorama
While Prisma Access, Cloud NGFW and Panorama appliances remain unaffected by this vulnerability, the risk of unauthenticated RCE exploitation is significantly elevated when the User-ID Authentication Portal is exposed to the public internet or untrusted networks.
>= 11.1.7-h6 (ETA: 05/28)
>= 11.1.10-h25 (ETA: 05/13)
>= 11.1.13-h5 (ETA: 05/13)
>= 11.1.15 (ETA: 05/28)
PAN-OS 10.2
< 10.2.7-h34
< 10.2.10-h36
< 10.2.13-h21
< 10.2.16-h7
< 10.2.18-h6
>= 10.2.7-h34 (ETA: 05/28)
>= 10.2.10-h36 (ETA: 05/13)
>= 10.2.13-h21 (ETA: 05/28)
>= 10.2.16-h7 (ETA: 05/28)
>= 10.2.18-h6 (ETA: 05/13)
Prisma Access
None
All
The cybersecurity vendor states that the issue doesn’t impact Prisma Access, Cloud NGFW and Panorama appliances.
This issue does not impact Cloud NGFW or Panorama appliances.
organisation
Prisma Access
None
>= 11.1.7-h6 (ETA: 05/28)
>= 11.1.10-h25 (ETA: 05/13)
>= 11.1.13-h5 (ETA: 05/13)
>= 11.1.15 (ETA: 05/28)
PAN-OS 10.2
< 10.2.7-h34
< 10.2.10-h36
< 10.2.13-h21
< 10.2.16-h7
< 10.2.18-h6
>= 10.2.7-h34 (ETA: 05/28)
>= 10.2.10-h36 (ETA: 05/13)
>= 10.2.13-h21 (ETA: 05/28)
>= 10.2.16-h7 (ETA: 05/28)
>= 10.2.18-h6 (ETA: 05/13)
Prisma Access
None
All
The cybersecurity vendor states that the issue doesn’t impact Prisma Access, Cloud NGFW and Panorama appliances.
organisation
User-ID Authentication Portal
Adhering to best practice guidelines by restricting User-ID Authentication Portal access exclusively to trusted internal IP addresses and ensuring the portal is not publicly reachable will greatly mitigate this risk.
organisation
IP
Adhering to best practice guidelines by restricting User-ID Authentication Portal access exclusively to trusted internal IP addresses and ensuring the portal is not publicly reachable will greatly mitigate this risk.
“The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the
best practice guidelines
by restricting access to only trusted internal IP addresses.”
“This vulnerability is specific to a limited number of customers with their User-ID Authentication Portal (Captive Portal) exposed to the public internet or untrusted IP addresses.
organisation
User-ID Authentication Portal (Captive Portal
“This vulnerability is specific to a limited number of customers with their User-ID Authentication Portal (Captive Portal) exposed to the public internet or untrusted IP addresses.
organisation
RCE
A week later, the attackers successfully achieved RCE against the device and injected shellcode.
organisation
EarthWorm
RCE was then achieved on the second device, where EarthWorm and ReverseSocks5 were downloaded.
“Post-exploitation activity includes deployment of publicly available tunneling tools (EarthWorm, ReverseSocks5), Active Directory enumeration using credentials likely obtained from the firewall, and the systematic destruction of logs and other evidence of compromise.”
EarthWorm has been used in past attacks associated with several China-linked threat actors, including ,
APT41
,
CL-STA-0046
, and
Volt Typhoon
.
threat_actor
Volt Typhoon
“Post-exploitation activity includes deployment of publicly available tunneling tools (EarthWorm, ReverseSocks5), Active Directory enumeration using credentials likely obtained from the firewall, and the systematic destruction of logs and other evidence of compromise.”
EarthWorm has been used in past attacks associated with several China-linked threat actors, including ,
APT41
,
CL-STA-0046
, and
Volt Typhoon
.
EarthWorm has reportedly been used by the threat actor behind
CL-STA-0046
,
Volt Typhoon
,
UAT-8337
and
APT41
.
The tool has previously been linked to threat groups including Volt Typhoon and APT41.
ReverseSocks5 is another open-source networking tool designed to bypass firewalls and NAT protections by creating outbound connections from compromised systems to attacker-controlled servers.
threat_actor
APT41
“Post-exploitation activity includes deployment of publicly available tunneling tools (EarthWorm, ReverseSocks5), Active Directory enumeration using credentials likely obtained from the firewall, and the systematic destruction of logs and other evidence of compromise.”
EarthWorm has been used in past attacks associated with several China-linked threat actors, including ,
APT41
,
CL-STA-0046
, and
Volt Typhoon
.
EarthWorm has reportedly been used by the threat actor behind
CL-STA-0046
,
Volt Typhoon
,
UAT-8337
and
APT41
.
The tool has previously been linked to threat groups including Volt Typhoon and APT41.
ReverseSocks5 is another open-source networking tool designed to bypass firewalls and NAT protections by creating outbound connections from compromised systems to attacker-controlled servers.
organisation
NAT
The tool has previously been linked to threat groups including Volt Typhoon and APT41.
ReverseSocks5 is another open-source networking tool designed to bypass firewalls and NAT protections by creating outbound connections from compromised systems to attacker-controlled servers.
ReverseSocks5
ReverseSocks5 is an open-source networking tool used to bypass firewalls or NAT by establishing an outbound connection from a target machine to a controller, rather than the other way around.
organisation
Restrict User-ID Authentication Portal
Restrict User-ID Authentication Portal access to only trusted zones and in addition, disable Response Pages in the Interface Management Profile attached to every L3 interface in any zone where untrusted/internet traffic can ingress.
organisation
Response Pages
Restrict User-ID Authentication Portal access to only trusted zones and in addition, disable Response Pages in the Interface Management Profile attached to every L3 interface in any zone where untrusted/internet traffic can ingress.
organisation
the Interface Management Profile
Restrict User-ID Authentication Portal access to only trusted zones and in addition, disable Response Pages in the Interface Management Profile attached to every L3 interface in any zone where untrusted/internet traffic can ingress.
organisation
Keep Response Pages
Keep Response Pages enabled only on interfaces in trust/internal zones where legitimate users' browsers ingress.
organisation
Live Community
Refer to Step 6 of the linked
Live Community article
and
Knowledgebase article
for steps to restrict access.
organisation
Disable User-ID Authentication Portal
Disable User-ID Authentication Portal if not required.
organisation
Threat ID 510019
Customers with an Advanced Threat Prevention subscription can block attacks for this vulnerability by enabling Threat ID 510019 from Applications and Threats content version 9097-10022.
organisation
Applications
Customers with an Advanced Threat Prevention subscription can block attacks for this vulnerability by enabling Threat ID 510019 from Applications and Threats content version 9097-10022.
organisation
CL-STA-1132
The reliance of the attackers behind CL-STA-1132 on open-source tooling, rather than proprietary malware, minimized signature-based detection and facilitated seamless environment integration.
“The reliance of the attackers behind CL-STA-1132 on open-source tooling, rather than proprietary malware, minimized signature-based detection and facilitated seamless environment integration.
organisation
Cyber Threat Alliance
Palo Alto Networks has shared our findings with our fellow Cyber Threat Alliance (CTA) members.
organisation
CTA
Palo Alto Networks has shared our findings with our fellow Cyber Threat Alliance (CTA) members.
organisation
Cloud-Delivered Security Services
Cloud-Delivered Security Services for the Next-Generation Firewall
Advanced URL Filtering
and
Advanced DNS Security
identify known URLs and domains associated with this activity as malicious.
organisation
DNS Security
Cloud-Delivered Security Services for the Next-Generation Firewall
Advanced URL Filtering
and
Advanced DNS Security
identify known URLs and domains associated with this activity as malicious.
infrastructure
12.1
Below is the list of impacted products:
Versions
Affected
Unaffected
Cloud NGFW
None
All
PAN-OS 12.1
< 12.1.4-h5
< 12.1.7
>= 12.1.4-h5 (ETA: 05/13)
>= 12.1.7
infrastructure
12.1.4-h5
Below is the list of impacted products:
Versions
Affected
Unaffected
Cloud NGFW
None
All
PAN-OS 12.1
< 12.1.4-h5
< 12.1.7
>= 12.1.4-h5 (ETA: 05/13)
>= 12.1.7
infrastructure
12.1.7
Below is the list of impacted products:
Versions
Affected
Unaffected
Cloud NGFW
None
All
PAN-OS 12.1
< 12.1.4-h5
< 12.1.7
>= 12.1.4-h5 (ETA: 05/13)
>= 12.1.7
organisation
ETA
Below is the list of impacted products:
Versions
Affected
Unaffected
Cloud NGFW
None
All
PAN-OS 12.1
< 12.1.4-h5
< 12.1.7
>= 12.1.4-h5 (ETA: 05/13)
>= 12.1.7
May 8, 2026
Threat actors used a General Document Context (Unidentified Python Script) to target Palo Alto PAN-OS.
Click on any entity below to view its context and source!
tactic
T1059.006 - Python
(Unidentified Python Script)
/tmp/R5, /var/R5 (ReverseSocks5)
Updated May 8, 2026, at 9:20 a.m. PT, to update the product protections section, adding Cortex AgentiX and updating the Applications and Threats content version.
May 9, 2026
Palo Alto PAN-OS, a network security system, was exploited by nation-state actors through a zero-day vulnerability.
May 13, 2026
Threat actors exploited a zero-day vulnerability in Palo Alto PAN-OS, targeting nation-state actors.
May 13
CyberScoop reported that a Palo Alto PAN-OS zero-day exploit was being targeted by nation-state actors.
Click on any entity below to view its context and source!
organisation
CyberScoop
We have observed limited exploitation of this issue and are working to release software fixes, with the first updates expected to be available on May 13,” a Palo Alto Networks spokesperson told CyberScoop.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
EarthWorm
Earthworm is an
open-source
network tunneling tool written in C that operates on Windows, Linux, macOS and ARM/MIPS-based platforms.
Consequently, this campaign demonstrates that operational restraint—specifically the use of non-persistent access windows—is a primary factor in maintaining long-term residency on edge infrastructure.
…2.2.0/ReverseSocks5-v2.2.0-linux-amd64.tar[.]gz (ReverseSocks5 Download)
e11f69b49b6f2e829454371c31ebf86893f82a042dae3f2faf63dcd84f97a584 (EarthWorm)
Safari/532.31 Mozilla/5.5 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
EarthWorm is an open-source tunneling tool written in C that works across Windows, Linux, macOS, and ARM/MIPS platforms.
Consequently, this campaign demonstrates that operational restraint—specifically the use of non-persistent access windows—is a primary factor in maintaining long-term residency on edge infrastructure.”
Follow me on Twitter:
@securityaffairs
and…
Metrics
infrastructure
Linux
Affected Product
EarthWorm
Earthworm is an
open-source
network tunneling tool written in C that operates on Windows, Linux, macOS and ARM/MIPS-based platforms.
…/php_sess (EarthWorm Download)
hxxps[:]//github[.]com/Acebond/ReverseSocks5/releases/download/v2.2.0/ReverseSocks5-v2.2.0-linux-amd64.tar[.]gz (ReverseSocks5 Download)
e11f69b49b6f2e829454371c31ebf86893f82a042dae3f2faf63dcd84f97a584 (EarthWorm)…
EarthWorm is an open-source tunneling tool written in C that works across Windows, Linux, macOS, and ARM/MIPS platforms.
Metrics
infrastructure
Macos
Affected Product
EarthWorm
Earthworm is an
open-source
network tunneling tool written in C that operates on Windows, Linux, macOS and ARM/MIPS-based platforms.
EarthWorm is an open-source tunneling tool written in C that works across Windows, Linux, macOS, and ARM/MIPS platforms.
Metrics
infrastructure
11.1
Software Version
Decoder capabilities necessitate PAN-OS 11.1 or a later version for Threat ID support.
Metrics
infrastructure
82.080.467
Software Version
+82.080.467.8774
Advanced WildFire
The
Advanced WildFire
machine-learning models and analysis techniques have been reviewed and updated in light of indicators associated with this activity.
Metrics
infrastructure
67.206.213
Software Version
Indicators of Compromise
67.206.213[.]86
136.0.8[.]48
146.70.100[.]69 (C2 Staging)
149.104.66[.]84
hxxp[:]//146.70.100[.]69:8000/php_sess (EarthWorm Download)
hxxps[:]//github[.]com/Acebond/ReverseSocks5/releases/download/v2.2.0/Rever…
Metrics
infrastructure
136.0.8
Software Version
Indicators of Compromise
67.206.213[.]86
136.0.8[.]48
146.70.100[.]69 (C2 Staging)
149.104.66[.]84
hxxp[:]//146.70.100[.]69:8000/php_sess (EarthWorm Download)
hxxps[:]//github[.]com/Acebond/ReverseSocks5/releases/download/v2.2.0/Rever…
Metrics
infrastructure
146.70.100
Software Version
Indicators of Compromise
67.206.213[.]86
136.0.8[.]48
146.70.100[.]69 (C2 Staging)
149.104.66[.]84
hxxp[:]//146.70.100[.]69:8000/php_sess (EarthWorm Download)
hxxps[:]//github[.]com/Acebond/ReverseSocks5/releases/download/v2.2.0/Rever…
Metrics
infrastructure
149.104.66
Software Version
Indicators of Compromise
67.206.213[.]86
136.0.8[.]48
146.70.100[.]69 (C2 Staging)
149.104.66[.]84
hxxp[:]//146.70.100[.]69:8000/php_sess (EarthWorm Download)
hxxps[:]//github[.]com/Acebond/ReverseSocks5/releases/download/v2.2.0/Rever…
Metrics
infrastructure
2.0
Software Version
…[:]//146.70.100[.]69:8000/php_sess (EarthWorm Download)
hxxps[:]//github[.]com/Acebond/ReverseSocks5/releases/download/v2.2.0/ReverseSocks5-v2.2.0-linux-amd64.tar[.]gz (ReverseSocks5 Download)
e11f69b49b6f2e829454371c31ebf86893f82a042dae3f2faf6…
Metrics
infrastructure
2.0-linux
Software Version
…8000/php_sess (EarthWorm Download)
hxxps[:]//github[.]com/Acebond/ReverseSocks5/releases/download/v2.2.0/ReverseSocks5-v2.2.0-linux-amd64.tar[.]gz (ReverseSocks5 Download)
e11f69b49b6f2e829454371c31ebf86893f82a042dae3f2faf63dcd84f97a584 (EarthW…
Metrics
infrastructure
532.31
Software Version
…2.2.0/ReverseSocks5-v2.2.0-linux-amd64.tar[.]gz (ReverseSocks5 Download)
e11f69b49b6f2e829454371c31ebf86893f82a042dae3f2faf63dcd84f97a584 (EarthWorm)
Safari/532.31 Mozilla/5.5 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
Metrics
infrastructure
5.5
Software Version
…2.2.0/ReverseSocks5-v2.2.0-linux-amd64.tar[.]gz (ReverseSocks5 Download)
e11f69b49b6f2e829454371c31ebf86893f82a042dae3f2faf63dcd84f97a584 (EarthWorm)
Safari/532.31 Mozilla/5.5 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
Metrics
infrastructure
10.0
Software Version
…2.2.0/ReverseSocks5-v2.2.0-linux-amd64.tar[.]gz (ReverseSocks5 Download)
e11f69b49b6f2e829454371c31ebf86893f82a042dae3f2faf63dcd84f97a584 (EarthWorm)
Safari/532.31 Mozilla/5.5 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
Metrics
infrastructure
537.36
Software Version
…2.2.0/ReverseSocks5-v2.2.0-linux-amd64.tar[.]gz (ReverseSocks5 Download)
e11f69b49b6f2e829454371c31ebf86893f82a042dae3f2faf63dcd84f97a584 (EarthWorm)
Safari/532.31 Mozilla/5.5 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0 (Attacker User Agent String)
/var/tmp/linuxap, /var/tmp/linuxda, /var/tmp/linuxupdate (Tunneling Tools)
/tmp/.c
Metrics
infrastructure
138.0.0
Software Version
Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0 (Attacker User Agent String)
/var/tmp/linuxap, /var/tmp/linuxda, /var/tmp/linuxupdate (Tunneling Tools)
/tmp/.c
Metrics
infrastructure
12.1
Software Version
Below is the list of impacted products:
Versions
Affected
Unaffected
Cloud NGFW
None
All
PAN-OS 12.1
< 12.1.4-h5
< 12.1.7
>= 12.1.4-h5 (ETA: 05/13)
>= 12.1.7
Metrics
infrastructure
12.1.4-h5
Software Version
Below is the list of impacted products:
Versions
Affected
Unaffected
Cloud NGFW
None
All
PAN-OS 12.1
< 12.1.4-h5
< 12.1.7
>= 12.1.4-h5 (ETA: 05/13)
>= 12.1.7
Metrics
infrastructure
12.1.7
Software Version
Below is the list of impacted products:
Versions
Affected
Unaffected
Cloud NGFW
None
All
PAN-OS 12.1
< 12.1.4-h5
< 12.1.7
>= 12.1.4-h5 (ETA: 05/13)
>= 12.1.7
Intelligence Sources
Security Affairs
2026-05-07
CyberScoop
2026-05-06
Security Affairs
2026-05-07
Nation-state actors exploit Palo Alto PAN-OS zero-day for weeks
Security Affairs
Palo Alto
2026-05-07
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-06-29T06:14
Comprehensive Tactical Telemetry
Highly Correlated Entities
49x
organisation
Identified Entity
IoT
entity
16x
infrastructure
Software Version
11.1
version
10x
attribution
Attributing Entity
Cortex AgentiX
authority
9x
timeline
Temporal Reference
May 6, 2026
date
6x
target region
Target Country
United Kingdom
country
5x
tactic
Cyber Operation Type
Privilege Escalation
tactic
4x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
3x
target region
Target Region
MIDDLE_EAST
region
3x
infrastructure
Affected Product
Windows
software
2x
general metric
+1
866
+1
2x
threat actor
APT Group
Volt Typhoon
actor
Contextual Telemetry
Context Block
10 METRICS
general metric
Incident
42
incident
general metric
+65.6983.8730
50
+65.6983.8730
vulnerability
Exploited CVE
CVE-2026-0300
cve
general metric
Cve-2026
300
cve-2026
general metric
Pan Os
11
pan os
general metric
Step
6
step
general metric
Threat Id
510,019
threat id
source region
Origin Country
China
country
vulnerability
CVSS Score
9
score
general metric
Exposed Series Firewalls
5,800
exposed series firewalls
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.