Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsYes. Palo Alto Networks Unit 42 reported limited exploitation of CVE-2026-0300, a zero-day in the PAN-OS User-ID Authentication Portal, also called Captive Portal. The flaw can let an unauthenticated attacker run code as root on affected PA-Series and VM-Series firewalls. Unit 42 tracks the activity as CL-STA-1132, a cluster of likely state-sponsored activity; it has not named a government sponsor.
What the PAN-OS vulnerability does
CVE-2026-0300 is a buffer overflow in the User-ID Authentication Portal (Captive Portal) service. Specially crafted packets can trigger the flaw and allow unauthenticated remote code execution with root privileges on a vulnerable firewall. The Cyber Security Agency of Singapore (CSA) assigned it a CVSS v4.0 score of 9.3 out of 10 in its May 6, 2026 advisory; CERT-EU also reported a score of 9.3 in its May 6 advisory.
Exposure is substantially higher when the portal can be reached from the public internet or other untrusted networks. Unit 42 says Prisma Access, Cloud NGFW, and Panorama appliances are not affected by this vulnerability. The reporting does not mean that all Palo Alto Networks products—or every PAN-OS firewall—are vulnerable.
Which PAN-OS releases were listed as affected
In advisories dated May 6, 2026, CSA and CERT-EU listed the following affected release ranges and fixed-release thresholds. These are a snapshot, not a substitute for checking Palo Alto Networks’ live advisory: release branches and hotfix guidance can change, and administrators need the supported upgrade path for their exact installed version.
Free tools Windows power users keep installed
One-click scans. No signup required.
| PAN-OS branch | Affected versions and listed fixed thresholds | Source |
|---|---|---|
| 12.1 | Versions prior to 12.1.4-h5 or 12.1.7 | CSA and CERT-EU, May 6, 2026 |
| 11.2 | Versions prior to 11.2.4-h17, 11.2.7-h13, 11.2.10-h6, or 11.2.12 | CSA and CERT-EU, May 6, 2026 |
| 11.1 | Versions prior to 11.1.4-h33, 11.1.6-h32, 11.1.7-h6, 11.1.10-h25, 11.1.13-h5, or 11.1.15 | CSA and CERT-EU, May 6, 2026 |
| 10.2 | Versions prior to 10.2.7-h34, 10.2.10-h36, 10.2.13-h21, 10.2.16-h7, or 10.2.18-h6 | CSA and CERT-EU, May 6, 2026 |
What Unit 42 observed in the reported attacks
Unit 42 described a sequence of activity against targeted environments; it is an incident report, not a claim that every exploitation follows the same steps. It said unsuccessful attempts began on April 9, 2026, followed about a week later by successful remote code execution and shellcode injected into an nginx worker process.
#1 Best Overall
After gaining access, the attackers cleared crash kernel messages, deleted nginx crash entries and records, and removed crash core dumps. Four days later, Unit 42 observed tools deployed with root privileges and Active Directory enumeration using credentials likely obtained from the firewall’s service account. The reported targeting included domain root and DomainDnsZones.
On April 29, 2026, Unit 42 said the attackers conducted a SAML flood that caused a second device to become active and inherit the same internet-facing traffic. They then achieved remote code execution on that device and downloaded EarthWorm and ReverseSocks5, which Unit 42 identifies as tunneling tools. The incident account also describes removal of audit-log evidence and deletion of a SUID privilege-escalation binary.
Rank #2
- Item Package Quantity - 1
- Product Type - ELECTRONIC SWITCH
- This pre-owned product has been professionally inspected, tested and cleaned by Amazon qualified vendors.
- Accessories may not be original, but will be compatible and fully functional. Product may come in generic box.
How to reduce exposure
Unit 42, CSA, and CERT-EU advise restricting portal access to trusted zones or disabling the portal if it is not needed. Which option is workable depends on whether the environment relies on the portal for legitimate users.
| Option | When it fits | Action |
|---|---|---|
| Restrict access | The portal is required for users on trusted or internal networks | Limit User-ID Authentication Portal access to trusted zones. Unit 42 specifically advises disabling Response Pages in the Interface Management Profile on Layer 3 interfaces in zones where untrusted or internet traffic can enter, and keeping Response Pages enabled only on trusted/internal interfaces where legitimate users’ browsers enter. |
| Disable the portal | The portal is not required | Disable the User-ID Authentication Portal rather than leaving it reachable unnecessarily. |
Apply the security update that Palo Alto Networks identifies for the firewall’s exact installed release, and follow the vendor’s current upgrade guidance. Because the fixed-release list may change, confirm it in the live Palo Alto Networks advisory before scheduling or making an upgrade.
Rank #3
What to do if you suspect a firewall was compromised
Do not treat a successful software update or a restricted portal as proof that an earlier intrusion did not happen. Unit 42’s account includes log and crash-record cleanup, root-level tooling, tunneling, and possible use of firewall service-account credentials to enumerate Active Directory. Those observations make the reported firewall and the credentials it may hold relevant to an investigation.
Palo Alto Networks says Unit 42 Incident Response can assist with a suspected compromise or provide a proactive assessment. The public incident report does not establish program or referral terms.
Quick Recap
What “limited exploitation” means here
CSA’s May 6, 2026 advisory said, “Limited exploitation in the wild has been observed.” That is the scope statement available from the cited reporting; it does not establish a victim count or indicate how prevalent exploitation is now. Unit 42 characterized CL-STA-1132 as likely state-sponsored activity, but the reporting does not identify a sponsoring government.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

