CVE-2026-0300CISA KEV: Actively Exploited

Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability

Published May 6, 2026·Updated May 6, 2026

Description

Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.

Public Exploits & PoCs8 found

[POC] CVE-2026-0300 — CVE-2026-0300-PANOS-RCE

PAN-OS User-ID Captive Portal Buffer Overflow RCE Scanner & Checker

[POC] CVE-2026-0300 — CVE-2026-0300

CVE-2026-0300 PAN-OS 12.1, 11.2, 11.1, 10.2

[POC] CVE-2026-0300 — CVE-2026-0300

PAN-OS CVE-2026-0300 Non-Destructive Exposure Survey Tool

[POC] CVE-2026-0300 — CVE-2026-0300-PANOS

Security Research and Proof-of-Concept (PoC) for CVE-2026-0300 : Unauthenticated Remote Code Execution (RCE) in Palo Alto Networks PAN-OS User-ID Portal.

[POC] CVE-2026-0300 — cve-2026-0300-audit

Read-only audit tooling for CVE-2026-0300 (PAN-OS User-ID Authentication Portal exposure)

[POC] CVE-2026-0300 — CVE-2026-0300

CVE-2026-0300

[POC] CVE-2026-0300 — CVE-2026-0300

a honeypot for CVE-2026-0300

[POC] CVE-2026-0300 — PAN-OS-User-ID-Buffer-Overflow-PoC

A research-grade Proof-of-Concept (PoC) for CVE-2026-0300, targeting the Buffer Overflow vulnerability in Palo Alto Networks PAN-OS User-ID™ Authentication Portal (CWE-787).

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free