Critical PAN-OS vulnerability already under fire
Palo Alto Networks has reported a critical security vulnerability in its PAN-OS operating system that is already being actively exploited on the internet. The flaw allows unauthenticated attackers to execute arbitrary code with root privileges on affected firewall systems. Particularly serious: updates will not be available for another one to several weeks.
The technical details of the vulnerability
The security flaw is a buffer overflow in the User-ID authentication portal, also known as the captive portal. Tracked as CVE-2026-0300, the vulnerability received a CVSS4 score of 9.3 and thus the risk rating "critical".
Attackers can exploit the flaw by sending carefully crafted packets to affected firewalls in the PA and VM series. This gives them the ability to inject and execute arbitrary code with root privileges.
Affected systems and versions
The vulnerability affects the following PAN-OS versions:
- PAN-OS 12.1
- PAN-OS 11.2
- PAN-OS 11.1
- PAN-OS 10.2
According to Palo Alto Networks, Cloud NGFW, Prisma Access and Panorama appliances are explicitly not affected.
Immediate protective measures required
Since the vulnerability is already being actively exploited, IT managers are urged to take immediate countermeasures. Palo Alto Networks recommends two temporary approaches:
Disabling the captive portal
The most effective immediate measure is to completely disable the User-ID authentication portal. As it is not configured by default, only systems where the portal was explicitly enabled are affected.
Restricting access permissions
If disabling the portal is not possible, access should be restricted to trusted zones. This measure reduces the CVSS4 score from 9.3 to 8.7 and thus lowers the risk from "critical" to "high".
Observed attacks and configuration errors
Palo Alto Networks confirms that limited abuse of the vulnerability has already been observed. On the affected devices, access was possible from untrusted IP addresses and in some cases even from the open internet.
The vendor stresses that such configurations contradict security best practices. This underlines the importance of a security-oriented baseline configuration of firewall systems.
Timeline of the planned updates
The availability of the security updates is planned in stages:
Available on 13 May:
- 12.1.4-h5
- 11.2.7-h13
- 11.2.10-h6
- 11.1.4-h33
- 11.1.6-h32
- 11.1.10-h25
- 11.1.13-h5
- 10.2.10-h36
- 10.2.18-h6
Available on 28 May:
- 12.1.7
- 11.2.4-h17
- 11.2.12
- 11.1.7-h6
- 11.1.15
- 10.2.7-h34
- 10.2.13-h21
- 10.2.16-h7
Placing the flaw in the security context
This vulnerability is part of a series of security problems at Palo Alto Networks. Back in January, vulnerabilities in the firewalls became known that allowed attackers to force the appliances into maintenance mode and thereby bypass the firewall protection.
For companies with critical infrastructure, the combination of active attacks and the delay in updates is particularly problematic. The fact that the vulnerability is already being exploited considerably increases the pressure to act.
Recommendations for IT managers
IT administrators should take the following measures immediately:
- Immediately review all PAN-OS installations for active captive portal configurations
- Disable the User-ID authentication portal wherever possible
- Restrict access permissions to trusted IP ranges as an alternative
- Increase monitoring of affected systems for suspicious activity
- Plan the update installation in line with the availability dates
Outlook and long-term security strategy
The case illustrates the importance of a multi-layered security strategy. Alongside the prompt installation of security updates, preventive configuration measures and continuous monitoring are indispensable.
Companies should regularly check their firewall configurations for compliance with security best practices. Restricting management access to trusted network segments can considerably reduce risk in the case of future vulnerabilities as well.
The staggered release of the updates over several weeks makes clear that temporary protective measures must remain an essential building block of security management.