CVE-2026-0300

KEV
🔴 Łataj teraz

Przepełnienie bufora w portalu uwierzytelniania User-ID w PAN-OS pozwala na zdalne wykonanie kodu.

CVSS
9.8
EPSS
5.3%
Exploit
weaponized
Vendor
paloaltonetworks
Opis źródłowy (NVD)

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.

buffer-overflow Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.8
CISA KEV (aktywnie wykorzystywane)Tak
FIRST EPSS (prawdopodobieństwo exploita)5.3%
Opublikowano (NVD)2026-05-06 19:16:35 UTC
Ostatnia modyfikacja (NVD)2026-05-07 17:46:44 UTC
Referencje