← Back to CVE List
Vulnerability Intelligence Report
PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal

CVE-2026-0300

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.

CISA KEV SSVC: Active Exploitation Automatable
CVSS Base Score
9.3
CRITICAL
EPSS Probability:32.07%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-787 ↗CWE-787: Out-of-bounds Write

Affected Products & Versions

Vendor Product Affected Versions
Palo Alto Networks Cloud NGFW All (unaffected)
Palo Alto Networks PAN-OS 12.1.0 < 12.1.7 (affected), 11.2.0 < 11.2.12 (affected), 11.1.0 < 11.1.15 (affected), 10.2.0 < 10.2.18-h6 (affected)
Palo Alto Networks Prisma Access All (unaffected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
32.074%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityPalo Alto Networks, Inc. · Vendor · USA
Reserved2025-11-03T20:44:58
Published2026-05-06T18:57:39
Patch Date2026-05-05
Last Updated2026-07-14T12:45:19

LINK COPIED TO CLIPBOARD