The Lab · 2026-05-07 01:31:39 · GitHub Issues
A critical unauthenticated remote code execution vulnerability in Palo Alto Networks PAN-OS has been catalogued under CVE-2026-0300, with active exploitation already confirmed in the wild. The flaw resides in the PAN-OS User-ID Authentication Portal—commonly referred to as Captive Portal—and stems from a buffer overflo...
The Lab · 2026-05-07 10:31:43 · GitHub Issues
Security researchers have identified a critical zero-day vulnerability, tracked as CVE-2026-0300, affecting Palo Alto Networks PAN-OS firewall firmware. The flaw enables unauthenticated remote code execution (RCE) by exploiting the Captive Portal component, which handles user authentication on network gateways. The vul...
The Lab · 2026-05-08 04:16:10 · The Hacker News
Palo Alto Networks has confirmed that threat actors are actively targeting a critical vulnerability in its PAN-OS software, with exploitation attempts dating back to April 9, 2026. The flaw, tracked as CVE-2026-0300, carries a CVSS score of 9.3 out of 10, placing it among the most severe security weaknesses affecting e...