Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes. Palo Alto Networks Unit 42 reported limited exploitation of CVE-2026-0300, a zero-day in the PAN-OS User-ID Authentication Portal, also called Captive Portal. The flaw can let an unauthenticated attacker run code as root on affected PA-Series and VM-Series firewalls. Unit 42 tracks the activity as CL-STA-1132, a cluster of likely state-sponsored activity; it has not named a government sponsor.

What the PAN-OS vulnerability does

CVE-2026-0300 is a buffer overflow in the User-ID Authentication Portal (Captive Portal) service. Specially crafted packets can trigger the flaw and allow unauthenticated remote code execution with root privileges on a vulnerable firewall. The Cyber Security Agency of Singapore (CSA) assigned it a CVSS v4.0 score of 9.3 out of 10 in its May 6, 2026 advisory; CERT-EU also reported a score of 9.3 in its May 6 advisory.

Exposure is substantially higher when the portal can be reached from the public internet or other untrusted networks. Unit 42 says Prisma Access, Cloud NGFW, and Panorama appliances are not affected by this vulnerability. The reporting does not mean that all Palo Alto Networks products—or every PAN-OS firewall—are vulnerable.

Which PAN-OS releases were listed as affected

In advisories dated May 6, 2026, CSA and CERT-EU listed the following affected release ranges and fixed-release thresholds. These are a snapshot, not a substitute for checking Palo Alto Networks’ live advisory: release branches and hotfix guidance can change, and administrators need the supported upgrade path for their exact installed version.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
PAN-OS branch Affected versions and listed fixed thresholds Source
12.1 Versions prior to 12.1.4-h5 or 12.1.7 CSA and CERT-EU, May 6, 2026
11.2 Versions prior to 11.2.4-h17, 11.2.7-h13, 11.2.10-h6, or 11.2.12 CSA and CERT-EU, May 6, 2026
11.1 Versions prior to 11.1.4-h33, 11.1.6-h32, 11.1.7-h6, 11.1.10-h25, 11.1.13-h5, or 11.1.15 CSA and CERT-EU, May 6, 2026
10.2 Versions prior to 10.2.7-h34, 10.2.10-h36, 10.2.13-h21, 10.2.16-h7, or 10.2.18-h6 CSA and CERT-EU, May 6, 2026

What Unit 42 observed in the reported attacks

Unit 42 described a sequence of activity against targeted environments; it is an incident report, not a claim that every exploitation follows the same steps. It said unsuccessful attempts began on April 9, 2026, followed about a week later by successful remote code execution and shellcode injected into an nginx worker process.

After gaining access, the attackers cleared crash kernel messages, deleted nginx crash entries and records, and removed crash core dumps. Four days later, Unit 42 observed tools deployed with root privileges and Active Directory enumeration using credentials likely obtained from the firewall’s service account. The reported targeting included domain root and DomainDnsZones.

On April 29, 2026, Unit 42 said the attackers conducted a SAML flood that caused a second device to become active and inherit the same internet-facing traffic. They then achieved remote code execution on that device and downloaded EarthWorm and ReverseSocks5, which Unit 42 identifies as tunneling tools. The incident account also describes removal of audit-log evidence and deletion of a SUID privilege-escalation binary.

Rank #2
Palo Alto Software Palo Alto 3050 [PA-3050] Network Security Firewall Appliance (Renewed)
  • Item Package Quantity - 1
  • Product Type - ELECTRONIC SWITCH
  • This pre-owned product has been professionally inspected, tested and cleaned by Amazon qualified vendors.
  • Accessories may not be original, but will be compatible and fully functional. Product may come in generic box.

How to reduce exposure

Unit 42, CSA, and CERT-EU advise restricting portal access to trusted zones or disabling the portal if it is not needed. Which option is workable depends on whether the environment relies on the portal for legitimate users.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Option When it fits Action
Restrict access The portal is required for users on trusted or internal networks Limit User-ID Authentication Portal access to trusted zones. Unit 42 specifically advises disabling Response Pages in the Interface Management Profile on Layer 3 interfaces in zones where untrusted or internet traffic can enter, and keeping Response Pages enabled only on trusted/internal interfaces where legitimate users’ browsers enter.
Disable the portal The portal is not required Disable the User-ID Authentication Portal rather than leaving it reachable unnecessarily.

Apply the security update that Palo Alto Networks identifies for the firewall’s exact installed release, and follow the vendor’s current upgrade guidance. Because the fixed-release list may change, confirm it in the live Palo Alto Networks advisory before scheduling or making an upgrade.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to do if you suspect a firewall was compromised

Do not treat a successful software update or a restricted portal as proof that an earlier intrusion did not happen. Unit 42’s account includes log and crash-record cleanup, root-level tooling, tunneling, and possible use of firewall service-account credentials to enumerate Active Directory. Those observations make the reported firewall and the credentials it may hold relevant to an investigation.

Palo Alto Networks says Unit 42 Incident Response can assist with a suspected compromise or provide a proactive assessment. The public incident report does not establish program or referral terms.

What “limited exploitation” means here

CSA’s May 6, 2026 advisory said, “Limited exploitation in the wild has been observed.” That is the scope statement available from the cited reporting; it does not establish a victim count or indicate how prevalent exploitation is now. Unit 42 characterized CL-STA-1132 as likely state-sponsored activity, but the reporting does not identify a sponsoring government.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.