A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2026-0300

Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability

Published
2026-05-06
Modified
2026-07-31
Sources
cisa-kev

Summary

Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.