INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

PAN-OS Zero-Day Exploited for Unauthenticated Remote Code Execution

| 2026-05-07 10:57 CRITICAL HIGH
Executive Summary AI-generated
The recent discovery of a critical-severity vulnerability in PAN-OS software has exposed thousands of internet-connected firewalls, including those from Palo Alto Networks. The CVE-2026-0300 zero-day attack allows unauthenticated remote code execution (RCE) on these devices, which are often targeted by state-sponsored threat groups due to their lack of logging and security software. As a result, the attackers have been successfully exploiting this vulnerability for nearly a month, with unsuccessful attempts reported starting from April 9, 2026. The EarthWorm tool has also been used in previous attacks linked to Chinese-speaking threat groups, highlighting the potential for widespread exploitation.
Technical Mitigations AI-generated
* Restrict access to trusted zones: Customers should restrict access to the PAN-OS User-ID Authentication Portal by only allowing trusted zones, or disable it if that's not possible. This can be done from the User-ID Authentication Portal Settings page under Device > User Identification > Authentication Portal Settings -> Enable Authentication Portal. * Disable remote code execution (RCE): Admins should check their firewalls for vulnerable services and disable them until security updates are available, which is expected to roll out next Wednesday, May 13. This will mitigate the risk of unauthenticated RCE attacks. * Use secure protocols: Customers can use secure communication protocols such as HTTPS or SFTP instead of HTTP to encrypt data transmitted over the network. * Keep firewalls up-to-date: Palo Alto Networks recommends that customers keep their firewalls and other security software up-to-date with the latest patches, which are expected to be released soon. This will help prevent exploitation of known vulnerabilities like CVE-2026-0300. * Implement logging and monitoring: Customers should implement logging and monitoring mechanisms to detect potential threats and respond quickly in case of an attack.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Volt TyphoonVolt TyphoonAPT41APT41 CVE-2026-0300CVE-2026-0300
Target & Sectors
EUROPE EUROPE MIDDLE_EAST MIDDLE_EAST NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎April 9, 2026
Threat actors exploited a Palo Alto Networks firewall zero-day vulnerability for nearly a month.
organisation RCE
organisation EarthWorm
organisation NAT
threat_actor Volt Typhoon
threat_actor APT41
organisation User-ID Authentication Portal Settings
‎April 29, 2026
Threat actors used a zero-day exploit in the Palo Alto Networks firewall to target and compromise the device on April 29, 2026.
‎May 6, 2026
Palo Alto Networks released a security advisory on May 6, 2026, to address CVE-2026-0300.
vulnerability CVE-2026-0300
tactic Buffer Overflow
organisation Palo Alto Networks
organisation User-ID
‎2026/05/06
Palo Alto Networks' VM-series firewalls were exploited for nearly a month.
organisation Palo Alto Networks VM-series
organisation BleepingComputer
organisation Panorama
‎2026/05/07
Palo Alto Networks customers received protections from and mitigations in the User-ID Authentication Portal, which was exploited by Earthworm to achieve unauthenticated remote code execution (RCE) in PAN-OS software.
organisation PAN
organisation User-ID Authentication Portal
organisation Palo Alto Networks Cortex Xpanse
organisation the User-ID Authentication Portal
organisation Current Scope of the Attack Using CVE-2026-0300
organisation IP
organisation Panorama
organisation Prisma Access
organisation EarthWorm
organisation NAT
threat_actor Volt Typhoon
threat_actor APT41
organisation IoT
infrastructure Windows
infrastructure Linux
infrastructure Macos
infrastructure 67.206.213
infrastructure 136.0.8
infrastructure 146.70.100
infrastructure 149.104.66
infrastructure 2.0
infrastructure 2.0-linux
infrastructure 532.31
infrastructure 5.5
infrastructure 10.0
infrastructure 537.36
organisation hxxps[:]//github[.]com/Acebond
organisation Mozilla/5.5 (Windows NT 10.0
organisation Win64
organisation KHTML
organisation Bridges
organisation Encapsulates
organisation RDP
organisation SSH
infrastructure 11.1
infrastructure 82.080.467
infrastructure 138.0.0
organisation Attacker User
organisation /tmp/.c
organisation Restrict User-ID Authentication Portal
organisation Response Pages
organisation the Interface Management Profile
organisation Keep Response Pages
organisation Live Community
organisation Disable User-ID Authentication Portal
organisation Threat ID 510019
organisation Applications
organisation CL-STA-1132
organisation Cyber Threat Alliance
organisation CTA
organisation Cloud-Delivered Security Services
organisation DNS Security
‎May 9
Threat actors exploited the CVE-2026-0300 zero-day in Palo Alto Networks firewalls for nearly a month.
vulnerability CVE-2026-0300
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
attribution Federal Civilian Executive Branch
attribution FCEB
‎May 12
Threat actors exploited a zero-day vulnerability in the Palo Alto Networks firewall for nearly two weeks.
organisation the Autonomous Validation Summit
general_metric 14 May
‎May 13
Palo Alto Networks' VM-series firewalls were exploited for nearly a month.
organisation Palo Alto Networks VM-series
organisation BleepingComputer
organisation Panorama
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎Macos
Affected Product
Metrics
infrastructure
‎11.1
Software Version
Metrics
infrastructure
‎82.080.467
Software Version
Metrics
infrastructure
‎67.206.213
Software Version
Metrics
infrastructure
‎136.0.8
Software Version
Metrics
infrastructure
‎146.70.100
Software Version
Metrics
infrastructure
‎149.104.66
Software Version
Metrics
infrastructure
‎2.0
Software Version
Metrics
infrastructure
‎2.0-linux
Software Version
Metrics
infrastructure
‎532.31
Software Version
Metrics
infrastructure
‎5.5
Software Version
Metrics
infrastructure
‎10.0
Software Version
Metrics
infrastructure
‎537.36
Software Version
Metrics
infrastructure
‎138.0.0
Software Version