
CVE-2026-0300
Buffer Overflow in User-ID™ Authentication Portal (Captive Portal) — Actively Exploited in the Wild
A critical buffer overflow vulnerability (CWE-787) in the User-ID Authentication Portal of PAN-OS allows unauthenticated attackers to achieve remote code execution with root privileges by sending specially crafted packets.
CVE ID: CVE-2026-0300
CVSS 4.0 Score: 9.3 (Critical)
Urgency: HIGHEST
Not affected: Cloud NGFW, Prisma Access, Panorama (in most configurations)
Exploitation Condition: The User-ID Authentication Portal must be enabled and reachable from untrusted networks (e.g., internet-exposed).
Actively exploited in the wild (as of May 6, 2026).
Limited real-world attacks have been observed targeting exposed User-ID portals.
Patches start rolling out from May 13, 2026.
/php/login.php or Captive Portal endpoints.Stay Secure — Review your firewall exposure today.
Last Updated: May 6, 2026
| PAN-OS Branch | Affected Versions | Fixed In (ETA) |
|---|
| 12.1 | < 12.1.4-h5, < 12.1.7 | 12.1.4-h5 (May 13) |
| 11.2 | All below specific hotfixes | Multiple (May 13–28) |
| 11.1 | All below specific hotfixes | Multiple (May 13–28) |
| 10.2 | All below specific hotfixes | Multiple (May 13–28) |