Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-0300 — CVE-2026-0300 | Kitploit
Tools/GitHubGitHub/0xblackash/cve-2026-0300
Vulnerability AnalysisExploitationWeb Application ExploitationNetwork SecurityPenetration TestingRed Teaming
GitHub0xblackash/cve-2026-0300

CVE-2026-0300

CVE-2026-0300

View Repository
134 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🚨 CVE-2026-0300 - Critical Unauthenticated Remote Code Execution in Palo Alto Networks PAN-OS

paloalto

Buffer Overflow in User-ID™ Authentication Portal (Captive Portal) — Actively Exploited in the Wild

Palo Alto Networks Severity Exploit


📋 Overview

A critical buffer overflow vulnerability (CWE-787) in the User-ID Authentication Portal of PAN-OS allows unauthenticated attackers to achieve remote code execution with root privileges by sending specially crafted packets.

CVE ID: CVE-2026-0300
CVSS 4.0 Score: 9.3 (Critical)
Urgency: HIGHEST


🛠️ Affected Products

  • PA-Series Firewalls
  • VM-Series Firewalls

Affected PAN-OS Versions

Not affected: Cloud NGFW, Prisma Access, Panorama (in most configurations)


🔍 Vulnerability Details

  • Type: Buffer Overflow (Out-of-bounds Write)
  • Component: User-ID™ Authentication Portal (Captive Portal)
  • Attack Vector: Network (Unauthenticated)
  • Privileges Required: None
  • User Interaction: None
  • Impact: Root-level arbitrary code execution

Exploitation Condition: The User-ID Authentication Portal must be enabled and reachable from untrusted networks (e.g., internet-exposed).


📸 Demo

CVE-2026-0300 0 CVE-2026-0300 1

⚠️ Exploitation Status

Actively exploited in the wild (as of May 6, 2026).

Limited real-world attacks have been observed targeting exposed User-ID portals.


🛡️ Mitigation & Workarounds (Immediate Action Required)

1. Recommended Workarounds (Until patches are available)

  • Restrict access to the User-ID Authentication Portal to trusted IP addresses only.
  • Disable the Captive Portal / User-ID portal if not required.
  • Block access to the portal on untrusted interfaces (e.g., via security policies).

2. Apply Official Patches

Patches start rolling out from May 13, 2026.


📌 References

  • Official Advisory: Palo Alto Networks - CVE-2026-0300
  • The Hacker News: PAN-OS Flaw Under Active Exploitation
  • SecurityWeek: Palo Alto Zero-Day Exploited

🛠️ Detection & Hunting Tips

  • Look for unusual traffic to /php/login.php or Captive Portal endpoints.
  • Monitor for unexpected processes or reboots on firewalls.
  • Enable PAN-OS threat prevention and strict zone-based policies.

Stay Secure — Review your firewall exposure today.


Last Updated: May 6, 2026

Download Tool
PAN-OS BranchAffected VersionsFixed In (ETA)
12.1< 12.1.4-h5, < 12.1.712.1.4-h5 (May 13)
11.2All below specific hotfixesMultiple (May 13–28)
11.1All below specific hotfixesMultiple (May 13–28)
10.2All below specific hotfixesMultiple (May 13–28)