Palo Alto Networks, a cybersecurity giant, is in the hot seat as a critical zero-day vulnerability in its PAN-OS software has been exploited to hack some of its firewall models. The vulnerability, tracked as CVE-2026-0300, is a buffer overflow affecting the User-ID Authentication Portal (Captive Portal) service. This flaw allows unauthenticated attackers to execute malicious code with root privileges via specially crafted packets, posing a significant threat to PA and VM series firewalls.
What makes this particularly concerning is the limited exploitation observed, indicating that sophisticated threat actors, often state-sponsored groups, have already leveraged the flaw in highly targeted attacks. Palo Alto Networks has confirmed that the vulnerability affects only those firewalls configured to use the User-ID Authentication Portal and exposed to untrusted IP addresses or the public internet. Interestingly, Prisma Access, Cloud NGFW, and Panorama appliances are not affected, highlighting the importance of proper configuration in mitigating such risks.
This isn't the first time Palo Alto Networks has faced such challenges. In 2024, seven vulnerabilities were exploited, including by state-sponsored hackers, and in 2025, only two vulnerabilities were successfully exploited in the wild. The company's widespread adoption across major enterprises and government organizations makes its firewalls prime targets for sophisticated threat actors. The CISA's Known Exploited Vulnerabilities (KEV) catalog currently includes 13 Palo Alto product vulnerabilities, but CVE-2026-0300 has not yet been included, suggesting that the threat is still emerging.
The upcoming patch release on May 13 and May 28 is a crucial step in addressing this vulnerability. However, it underscores the ongoing battle between cybersecurity vendors and threat actors. As Palo Alto Networks works to patch the zero-day, it serves as a stark reminder of the importance of proactive security measures and the need for constant vigilance in the ever-evolving landscape of cybersecurity.