CVE-2026-0300 is a do-now firewall exposure problem, not a routine vulnerability-management ticket. Palo Alto Networks rates the PAN-OS flaw as HIGHEST urgency and CRITICAL 9.3 severity, with exploit maturity listed as ATTACKED . The vulnerability is a buffer overflow in the User-ID Authentication Portal, also called Captive Portal, and government and vendor reports say it can allow unauthenticated code execution with root privileges on affected PA-Series and VM-Series firewalls
.
If the portal is reachable from the public internet or another untrusted network, the immediate goal is simple: remove that exposure, apply the appropriate Palo Alto fix when available for your deployment, and assess exposed devices for compromise.
The advisory characteristics are the kind security teams prioritize first: network attack vector, low attack complexity, no privileges required, no user interaction, no attack requirements, and automatable exploitation . Unit 42 says it is aware of limited exploitation and is tracking a likely state-sponsored activity cluster exploiting the vulnerability
. The Canadian Centre for Cyber Security also reported that Palo Alto received active-exploitation reports and that CISA added CVE-2026-0300 to the Known Exploited Vulnerabilities catalog on May 6, 2026
.
Limited exploitation does not make this safe to defer. The Center for Internet Security says exploitation has targeted User-ID Authentication Portals exposed to untrusted IP addresses or the public internet, while customers restricting sensitive portals to trusted internal networks are at greatly reduced risk . Unit 42 similarly says unauthenticated RCE risk is significantly elevated when the portal is exposed to the public internet or untrusted networks
.
Start with Palo Alto Networks PA-Series and VM-Series firewalls running PAN-OS where the User-ID Authentication Portal/Captive Portal is enabled . Public reporting on Palo Alto’s scoring notes a CVSS score of 9.3 when the portal is configured for internet or untrusted-network access, dropping to 8.7 when access is restricted to trusted internal IP addresses
. Lower risk is not the same as remediated risk: internally restricted systems still need the vendor-recommended update path
.
Unit 42 says Prisma Access, Cloud NGFW, and Panorama appliances are not affected by this vulnerability . That helps narrow the triage list, but it should not replace an audit of PA-Series and VM-Series firewall deployments, especially any environment where Captive Portal has been exposed to untrusted IP addresses
.
Inventory PAN-OS firewalls and identify which PA-Series and VM-Series devices have the User-ID Authentication Portal/Captive Portal enabled . For each one, record whether the portal is reachable from the internet, from any untrusted network, or only from trusted internal IP ranges. Treat public or untrusted reachability as the highest-priority condition because that is where exploitation risk is elevated
.
Restrict the User-ID Authentication Portal to trusted internal networks only. If that cannot be done reliably, disable portal access until the device can be remediated. Singapore’s Cyber Security Agency advises users and administrators of affected versions to restrict or disable portal access until security updates are available .
CERT-EU recommends updating affected appliances as soon as patches are available while applying workarounds and mitigations in the meantime . Use Palo Alto Networks’ CVE-2026-0300 advisory as the authoritative source for current affected-version and fixed-version guidance for your PAN-OS branch
.
Do not assume that a software update alone fixes the deployment risk. After patching, confirm that the User-ID Authentication Portal is not reachable from the public internet or untrusted networks unless a documented business requirement exists and compensating controls are in place. Restricting sensitive portals to trusted internal networks is described as a best-practice posture that greatly reduces risk .
Any affected firewall with a portal exposed to untrusted networks should get a compromise assessment before returning to normal trust. Preserve logs, review portal traffic, check for unexpected configuration changes, and look for post-exploitation activity. The reason is straightforward: successful exploitation can provide unauthenticated root-level code execution on the firewall .
For U.S. federal teams covered by CISA KEV processes, CVE-2026-0300 is not only a vendor advisory. The Canadian Centre for Cyber Security reports that CISA added the vulnerability to the KEV catalog on May 6, 2026 , and current reporting notes that federal agencies are directed to remediate KEV-listed vulnerabilities under BOD 22-01
.
Agency teams should maintain an evidence trail for asset discovery, portal restriction or disablement, patch status, fixed PAN-OS version validation, proof that no untrusted network path remains, and compromise assessment for any firewall that was exposed.
Keep mitigations in place until the correct fixed release is available and installed for the affected deployment. If the business cannot tolerate disabling Captive Portal, restrict access to trusted internal IP ranges and monitor closely. If neither patching nor reliable restriction is possible, isolate the firewall from untrusted access or remove the exposed service until remediation is complete. The residual exposure is network-reachable, unauthenticated, automatable, and already reported as exploited .
The minimum safe posture is clear: remove untrusted access to the User-ID Authentication Portal, follow Palo Alto’s advisory for patching, and investigate any exposed firewall before restoring normal trust .
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
CVE 2026 0300 is a critical PAN OS User ID Authentication Portal/Captive Portal flaw rated 9.3 and marked attacked; CISA added it to KEV on May 6, 2026.
CVE 2026 0300 is a critical PAN OS User ID Authentication Portal/Captive Portal flaw rated 9.3 and marked attacked; CISA added it to KEV on May 6, 2026. Highest risk systems are PA Series and VM Series firewalls where the portal is reachable from the internet or another untrusted network; internal only access lowers risk but does not replace patching.
Federal teams should run this through KEV/BOD 22 01 remediation evidence, while private organizations should use the same emergency posture because exploitation has been reported.