The Lab · 2026-05-07 01:31:39 · GitHub Issues
A critical unauthenticated remote code execution vulnerability in Palo Alto Networks PAN-OS has been catalogued under CVE-2026-0300, with active exploitation already confirmed in the wild. The flaw resides in the PAN-OS User-ID Authentication Portal—commonly referred to as Captive Portal—and stems from a buffer overflo...
The Lab · 2026-05-08 04:16:13 · The Hacker News
Palo Alto Networks has issued an emergency advisory warning of a critical buffer overflow flaw in its PAN-OS firewall operating system that threat actors are actively exploiting in the wild. The vulnerability, tracked as CVE-2026-0300, allows unauthenticated remote code execution and carries a CVSS score of 9.3, placin...
The Lab · 2026-05-11 14:10:38 · GitHub Issues
A stack-buffer-overflow vulnerability has been identified in GDAL's Arc/Info Binary Grid (AIG) raster driver, specifically in the `DecompressCCITTRLETile` function located in `aigccitt.c`. The vulnerability stems from a fundamental flaw in a size validation check: the function declares a 4000-byte stack buffer (`runs_b...
The Lab · 2026-05-13 09:18:26 · Mastodon:mastodon.social:#infosec
A critical stack-based buffer overflow vulnerability, tracked as CVE-2026-32661, has been identified in Canon GUARDIANWALL MailSuite, affecting versions 1.4.00 through 2.4.26. The flaw enables remote code execution, placing organizations running this email security platform at significant risk. A patch remains pending,...
The Lab · 2026-05-13 17:18:31 · Mastodon:mastodon.social:#osint
Palo Alto Networks ha emitido un aviso de seguridad de gravedad alta para una vulnerabilidad identificada como CVE-2026-0264, que afecta a la funcionalidad de DNS Proxy y DNS Server en sistemas PAN-OS. La vulnerabilidad consiste en un heap-based buffer overflow que permite a un atacante no autenticado ejecutar código r...