INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Palo Alto PAN-OS Flaw Exploited for Remote Code Execution

| 2026-05-06 08:52 CRITICAL HIGH
Executive Summary AI-generated
The Palo Alto Networks PAN-OS vulnerability, CVE-2026-0300, is a critical issue that affects the popular firewall operating system used by many Fortune 500 companies. The flaw allows unauthenticated remote code execution on certain firewalls with specific settings configured, particularly when the User-ID portal is exposed to the internet. A patch has not been published yet and Palo Alto Networks expects it will be included in releases over the next two weeks. Incident response firm Rapid7 warned that a patch is likely to be released for many versions by May 13, citing multiple bugs affecting lines of firewalls from 2024 that were exploited by cybercriminals and nation-state actors.
Technical Mitigations AI-generated
* Restrict access to User-ID Authentication Portal: Limiting access to the User-ID Authentication Portal per best practice guidelines can reduce the risk of exploitation. This includes restricting IP addresses and configuring settings to only allow trusted internal networks. * Use a secure authentication protocol: Implementing a secure authentication protocol, such as OAuth or OpenID Connect, can help prevent unauthorized access to systems with exposed User-ID Authentication Portals. * Implement rate limiting on User-ID Authentication Portal requests: Limiting the number of requests made to the User-ID Authentication Portal per minute can reduce the risk of exploitation by hackers who may try to flood the system with requests. * Monitor for suspicious activity: Regularly monitoring for suspicious activity, such as unusual login attempts or changes in access permissions, can help identify potential security incidents before they escalate into a full-blown attack.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-0300CVE-2026-0300
Target & Sectors
Global Scope
Incident Timeline
‎May 06, 2026
Threat actors exploited a critical buffer overflow vulnerability in Palo Alto Networks PAN-OS software.
organisation Palo Alto Networks
organisation PAN
tactic Buffer Overflow
organisation Vulnerability / Network Security
‎2026/05/06
Palo Alto Networks PAN-OS flaw exploited for remote code execution.
organisation Palo Alto Networks PAN-OS
organisation Palo Alto Networks
organisation PAN
organisation CVE-2026-0300
organisation the User-ID Authentication Portal
organisation CVSS
organisation User-ID
infrastructure 12.1
infrastructure 12.1.4-h5
infrastructure 12.1.7
organisation IP
organisation ETA
organisation Prisma Access None
organisation Prisma Access
organisation Panorama
organisation PAN-OS
organisation User-ID Authentication Portal
‎May 13, 2026
Palo Alto Networks' PAN-OS flaw was exploited for remote code execution.
infrastructure 12.1
infrastructure 12.1.4-h5
infrastructure 12.1.7
infrastructure 11.2
infrastructure 11.2.4-h17
infrastructure 11.2.7-h13
infrastructure 11.2.10-h6
infrastructure 11.2.12
infrastructure 11.1
infrastructure 11.1.4-h33
infrastructure 11.1.6-h32
infrastructure 11.1.7-h6
infrastructure 11.1.10-h25
infrastructure 11.1.13-h5
infrastructure 11.1.15
infrastructure 10.2
infrastructure 10.2.7-h34
infrastructure 10.2.10-h36
infrastructure 10.2.13-h21
infrastructure 10.2.16-h7
infrastructure 10.2.18-h6
organisation SecurityAffairs
organisation PAN-OS
‎May 13
Threat actors exploited a vulnerability in Palo Alto Networks PAN-OS to gain remote access.
Tactical Metrics
Metrics
infrastructure
‎12.1
Software Version
Metrics
infrastructure
‎12.1.4-h5
Software Version
Metrics
infrastructure
‎12.1.7
Software Version
Metrics
infrastructure
‎11.2
Software Version
Metrics
infrastructure
‎11.2.4-h17
Software Version
Metrics
infrastructure
‎11.2.7-h13
Software Version
Metrics
infrastructure
‎11.2.10-h6
Software Version
Metrics
infrastructure
‎11.2.12
Software Version
Metrics
infrastructure
‎11.1
Software Version
Metrics
infrastructure
‎11.1.4-h33
Software Version
Metrics
infrastructure
‎11.1.6-h32
Software Version
Metrics
infrastructure
‎11.1.7-h6
Software Version
Metrics
infrastructure
‎11.1.10-h25
Software Version
Metrics
infrastructure
‎11.1.13-h5
Software Version
Metrics
infrastructure
‎11.1.15
Software Version
Metrics
infrastructure
‎10.2
Software Version
Metrics
infrastructure
‎10.2.7-h34
Software Version
Metrics
infrastructure
‎10.2.10-h36
Software Version
Metrics
infrastructure
‎10.2.13-h21
Software Version
Metrics
infrastructure
‎10.2.16-h7
Software Version
Metrics
infrastructure
‎10.2.18-h6
Software Version