The Lab · 2026-05-06 07:31:37 · Heise Online
Palo Alto Networks hat vor einer bereits aktiv ausgenutzten kritischen Sicherheitslücke in seiner Firewall-Plattform PAN-OS gewarnt. Die Schwachstelle ermöglicht es Angreifern, die Authentifizierung zu umgehen und unbefugten Zugriff auf verwaltete Systeme zu erlangen. Das Unternehmen stuft die Vulnerability als kritisc...
The Lab · 2026-05-07 01:31:39 · GitHub Issues
A critical unauthenticated remote code execution vulnerability in Palo Alto Networks PAN-OS has been catalogued under CVE-2026-0300, with active exploitation already confirmed in the wild. The flaw resides in the PAN-OS User-ID Authentication Portal—commonly referred to as Captive Portal—and stems from a buffer overflo...
The Lab · 2026-05-07 10:31:43 · GitHub Issues
Security researchers have identified a critical zero-day vulnerability, tracked as CVE-2026-0300, affecting Palo Alto Networks PAN-OS firewall firmware. The flaw enables unauthenticated remote code execution (RCE) by exploiting the Captive Portal component, which handles user authentication on network gateways. The vul...
The Lab · 2026-05-08 04:16:10 · The Hacker News
Palo Alto Networks has confirmed that threat actors are actively targeting a critical vulnerability in its PAN-OS software, with exploitation attempts dating back to April 9, 2026. The flaw, tracked as CVE-2026-0300, carries a CVSS score of 9.3 out of 10, placing it among the most severe security weaknesses affecting e...
The Lab · 2026-05-13 17:18:31 · Mastodon:mastodon.social:#osint
Palo Alto Networks ha emitido un aviso de seguridad de gravedad alta para una vulnerabilidad identificada como CVE-2026-0264, que afecta a la funcionalidad de DNS Proxy y DNS Server en sistemas PAN-OS. La vulnerabilidad consiste en un heap-based buffer overflow que permite a un atacante no autenticado ejecutar código r...
The Lab · 2026-05-13 17:18:32 · Mastodon:mastodon.social:#osint
A newly disclosed vulnerability affecting Palo Alto Networks PAN-OS through the GlobalProtect interface has been flagged as a critical authentication bypass risk, according to a security advisory alert circulating in threat intelligence circles. The flaw, tracked as CVE-2026-0257, specifically targets the GlobalProtect...
The Lab · 2026-05-13 17:18:35 · Mastodon:mastodon.social:#osint
Palo Alto Networks has published a security advisory addressing CVE-2026-0263, a critical Remote Code Execution vulnerability affecting PAN-OS and specifically targeting IKEv2 processing functionality. The flaw enables unauthenticated attackers to execute arbitrary code on affected systems through malformed IKEv2 packe...