📋 Vulnerability Details
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2026-05-06
Added to CISA KEV: 2026-05-06 0 DAY BETWEEN CVE AND KEV
🌐 Internet Exposure (Shodan): 135k+ internet-facing instances →
Query: http.title:"GlobalProtect Portal"
View on Shodan ↗
This counts internet-facing PAN-OS devices via the GlobalProtect portal fingerprint. The vulnerable User-ID Authentication Portal runs on the same devices but is not directly indexed by Shodan, so this is a best-available estimate of the exposed population.
Checked: 2026-06-04
🎯 Recommendations:
- CRITICAL: Check for indicators of compromise - this vulnerability is in CISA KEV indicating active exploitation in the wild. Review logs, check for unauthorized access, verify system integrity
- IMMEDIATE: Apply security patches listed in the advisory (PAN-OS versions 12.1.7, 11.2.12, 11.1.15, 10.2.18-h6 and their respective hotfixes)
- URGENT: If patching cannot be completed immediately, restrict User-ID Authentication Portal access to only trusted internal IP addresses and disable Response Pages on internet-facing interfaces
- Deploy Threat Prevention signature ID 510019 if running PAN-OS 11.1+ with Threat Prevention subscription
- Consider disabling User-ID Authentication Portal entirely if not required
- Monitor for unusual network traffic patterns and unauthorized administrative access attempts
- Patch priority: CRITICAL - Apply within 72 hours due to active exploitation
🔍 Web Intelligence (Kagi · 2026-05-07)
CVE-2026-0300 is a critical vulnerability affecting
Palo Alto Networks PAN-OS software, specifically within the
User-ID™ Authentication Portals (also known as Captive Portal)
[1][6]. This vulnerability has been observed to be
actively exploited in the wild [3][6].
Key details regarding its exploitation include:
- Internet-Facing Applications/Services: The vulnerability specifically targets User-ID™ Authentication Portals that are exposed to untrusted IP addresses and/or the public internet [2][4].
- Evidence of Active Exploitation: CISA has added CVE-2026-0300 to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation [3]. Exploitation is described as active and limited [4][5].
- Attack Vectors and Exploitation Methods: The vulnerability is a case of unauthenticated remote code execution (RCE) [1]. An attacker can exploit this flaw by sending malicious packets over any network path that reaches the User-ID™ Authentication Portal. The attack vector is network-based from an unauthenticated source, with low attack complexity and no specific requirements [2][5]. It is a buffer overflow vulnerability [6].
- Targeted Attacks: While active exploitation has been detected, no specific victim organizations have been named in the disclosures [4].
- CISA Known Exploited Vulnerabilities Status: CVE-2026-0300 has been added to the CISA KEV Catalog [3]. Organizations are advised to use this catalog for vulnerability management prioritization [7].
- Technical Details about Internet Exploitability: The vulnerability allows for root RCE on firewalls [1]. It is described as an unauthenticated user-initiated buffer overflow [2]. The exploit is automatable [2][5].
Sources
-
Palo Alto PAN-OS Flaw Under Active Exploitation Enables Remote Code ...
CVE-2026-0300 exploited via public PAN-OS portal before May 13, 2026 patch, enabling root RCE on firewalls. ... The vulnerability, tracked as CVE-2026-0300, has been described as a case of unauthenticated remote code execution. It carries a CVSS score of ... ... CVE-2026-0300 exploited via public PA…
-
CVE-2026-0300 PAN-OS: Unauthenticated user initiated Buffer ...
Limited exploitation has been observed targeting Palo Alto Networks User-ID™ Authentication Portals that are exposed to untrusted IP addresses ... ... Exploit Maturity ATTACKED. Response Effort MODERATE. Recovery USER. Value Density CONCENTRATED. Attack Vector NETWORK. Attack Complexity LOW. Attack…
-
CISA Adds One Known Exploited Vulnerability to Catalog | CISA
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
-
Palo Alto CVE-2026-0300 Under Active Attack — Patch Due May 13
Exploitation Status: Active and Limited, Targeting Public-Facing Portal Instances Palo Alto Networks confirmed that active exploitation of CVE-2026-0300 has been detected, described as limited and targeting internet-accessible Captive Portal configurations. No specific victim organizations were name…
-
CVE-2026-0300 - Vulnerability Details - OpenCVE
An attacker can exploit this flaw by sending malicious packets over any network path that reaches the User‑ID™ Authentication Portal; thus the attack vector is inferred to be network‑based from an unauthenticated source. Generated by OpenCVE AI on May 6, 2026 at 21:38 UTC. cve-icon Mitre Data.No EPS…