Vulnerability Intelligence Report
PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
CVE-2026-0300
A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.
CISA KEV
SSVC: Active Exploitation
Automatable
CVSS Base Score
9.3
CRITICAL
EPSS Probability:32.07%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-787 ↗CWE-787: Out-of-bounds Write
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Palo Alto Networks | Cloud NGFW | All (unaffected) |
| Palo Alto Networks | PAN-OS | 12.1.0 < 12.1.7 (affected), 11.2.0 < 11.2.12 (affected), 11.1.0 < 11.1.15 (affected), 10.2.0 < 10.2.18-h6 (affected) |
| Palo Alto Networks | Prisma Access | All (unaffected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Palo Alto Networks, Inc. · Vendor · USA |
| Reserved | 2025-11-03T20:44:58 |
| Published | 2026-05-06T18:57:39 |
| Patch Date | 2026-05-05 |
| Last Updated | 2026-07-14T12:45:19 |
Community Chatter & Buzz