CVE-2026-0300

CRITICAL CISA KEV
Published May 6, 2026 Modified May 12, 2026 CWE-787

Description

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.

CVSS v3.1 Score

9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS — Exploit Prediction

0.0454
Probability of exploitation
0.89%
Percentile rank

EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild.

Added: May 6, 2026 Remediation due: May 9, 2026

Weakness Type (CWE)

CWE-787 Out-of-bounds Write

Affected Products

Vendor Product
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pan-os
paloaltonetworks pa-1410
paloaltonetworks pa-1420
paloaltonetworks pa-3410
paloaltonetworks pa-3420
paloaltonetworks pa-3430
paloaltonetworks pa-3440
paloaltonetworks pa-410
paloaltonetworks pa-410r
paloaltonetworks pa-410r-5g
paloaltonetworks pa-415
paloaltonetworks pa-415-5g
paloaltonetworks pa-440
paloaltonetworks pa-445
paloaltonetworks pa-450
paloaltonetworks pa-450r
paloaltonetworks pa-450r-5g
paloaltonetworks pa-455
paloaltonetworks pa-455-5g
paloaltonetworks pa-455r-5g
paloaltonetworks pa-460
paloaltonetworks pa-501
paloaltonetworks pa-505
paloaltonetworks pa-510
paloaltonetworks pa-520
paloaltonetworks pa-540
paloaltonetworks pa-5410
paloaltonetworks pa-5420
paloaltonetworks pa-5430
paloaltonetworks pa-5440
paloaltonetworks pa-5445
paloaltonetworks pa-545-poe
paloaltonetworks pa-5450
paloaltonetworks pa-550
paloaltonetworks pa-5540
paloaltonetworks pa-555-poe
paloaltonetworks pa-5550
paloaltonetworks pa-5560
paloaltonetworks pa-5570
paloaltonetworks pa-5580
paloaltonetworks pa-560
paloaltonetworks pa-7500
paloaltonetworks pa-7500-dpc-a
paloaltonetworks vm-100
paloaltonetworks vm-300
paloaltonetworks vm-50
paloaltonetworks vm-500
paloaltonetworks vm-700
siemens ruggedcom_ape1808_firmware
siemens ruggedcom_ape1808

References

Frequently Asked Questions

What is CVE-2026-0300? +
A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability. It has a CVSS v3.1 base score of 9.8 (CRITICAL). This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild.
How severe is CVE-2026-0300? +
CVE-2026-0300 has a CVSS v3.1 score of 9.8 out of 10, rated CRITICAL. This is a critical vulnerability that should be patched immediately. The EPSS score is 0.0454, placing it in the 1th percentile for exploitation probability.
What products are affected by CVE-2026-0300? +
CVE-2026-0300 affects products from paloaltonetworks, siemens, specifically: pa-1410, pa-1420, pa-3410, pa-3420, pa-3430, pa-3440, pa-410, pa-410r, pa-410r-5g, pa-415, pa-415-5g, pa-440, pa-445, pa-450, pa-450r, pa-450r-5g, pa-455, pa-455-5g, pa-455r-5g, pa-460, pa-501, pa-505, pa-510, pa-520, pa-540, pa-5410, pa-5420, pa-5430, pa-5440, pa-5445, pa-545-poe, pa-5450, pa-550, pa-5540, pa-555-poe, pa-5550, pa-5560, pa-5570, pa-5580, pa-560, pa-7500, pa-7500-dpc-a, pan-os, ruggedcom_ape1808, ruggedcom_ape1808_firmware, vm-100, vm-300, vm-50, vm-500, vm-700. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2026-0300? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2026-0300 — free, no signup required.

Start Free Scan