rootpwn

Vulnerabilities

Critical PAN-OS Buffer Overflow (CVE‑2026‑0300) Enables Root‑Level Code Execution

Palo Alto Networks has disclosed a 9.3‑scored buffer overflow in the User‑ID Authentication Portal of PAN‑OS that lets an unauthenticated attacker run arbitrary code with root privileges on PA‑Series and VM‑Series firewalls. Affected firmware spans versions before 12.1.4‑h5, 12.1.7, 11.2.4‑h17, and several earlier releases. No patch is live yet, but Palo Alto will ship one soon. Until then, limit or disable the captive portal. Immediate update is urged to shut the door on this critical flaw.

Palo Alto Networks just issued a critical advisory (CVE‑2026‑0300) that could let attackers hijack PA‑Series and VM‑Series firewalls with full root access. The flaw is a classic buffer overflow in the User‑ID Authentication Portal (captive portal) service.

What’s at Stake

Unauthenticated traffic can be crafted to overflow the portal’s buffer, spawning a shell that runs with root privileges. Palo Alto has seen limited exploitation in the wild, but the risk is high enough to warrant immediate action.

Affected Products

  • PA‑Series & VM‑Series firewalls using the User‑ID Authentication Portal
  • Versions prior to 12.1.4‑h5, 12.1.7, 11.2.4‑h17, 11.2.7‑h13, 11.2.10‑h6, 11.2.12, 11.1.4‑h33, 11.1.6‑h32, 11.1.7‑h6, 11.1.10‑h25, 11.1.13‑h5, 11.1.15, 10.2.7‑h34, 10.2.10‑h36, 10.2.13‑h21, 10.2.16‑h7, 10.2.18‑h6

How to Protect Now

  • Restrict captive‑portal traffic to trusted zones only.
  • Disable the User‑ID Authentication Portal if it’s not required.
  • Apply the upcoming patch as soon as it becomes available.
“Patching is the only definitive fix. Until then, limit or disable the portal to block the attack surface.”

Next Steps

Keep an eye on the Palo Alto advisory for the patch release date. Once the fix lands, reboot the affected appliances to ensure the new firmware takes effect. Monitor logs for any suspicious authentication portal traffic.

PaloAlto PAN-OS CVE20260300 BufferOverflow RootPrivilege Firewall

← All news