• News/
  • https://www.bleepingcomputer.com/news/security/pan-os-firewall-rce-zero-day-exploited-in-attacks-since-april-9/

Palo Alto Networks firewall zero-day exploited for nearly a month

BleepingComputer
·
Sergiu Gatlan
·
Published May 7, 2026
·
Updated

Palo Alto Networks warned customers that suspected state-sponsored hackers have been exploiting a critical-severity PAN-OS firewall zero-day vulnerability for nearly a month. Tracked as CVE-2026-0300, this remote code execution security flaw was found in the PAN-OS User-ID Authentication Portal (also known as the Captive Portal) and stems from a buffer overflow vulnerability that allows unauthenticated attackers to execute arbitrary code with root privileges on Internet-exposed PA-Series and VM-Series firewalls. "We are aware of only limited exploitation of CVE-2026-0300 at this time. Unit 42 is tracking CL-STA-1132, a cluster of likely state-sponsored threat activity exploiting CVE-2026-0300. The attacker behind this activity exploited CVE-2026-0300 to achieve unauthenticated remote code execution (RCE) in PAN-OS software," the company said. "Starting April 9, 2026, there were unsuccessful exploitation attempts against a PAN-OS device. A week later, the attackers successfully achieved RCE against the device and injected shellcode. Following the compromise, the attackers immediately conducted log cleanup to mitigate detection by clearing crash kernel messages, deleting nginx crash entries and nginx crash records, as well as removing crash core dump files." After compromising the victims' firewalls, the attackers deployed the open-source Earthworm and ReverseSocks5network tunneling tools, which can be used to create SOCKS v5 servers and proxy tunnels on compromised devices, r...

Read full article

Affected Software

3 affected components
Palo Alto Networks PAN-OS
Palo Alto Networks PA-Series
Palo Alto Networks VM-Series
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical-severity zero-day vulnerability in Palo Alto Networks' PAN-OS firewall that has been exploited by hackers.

2

What security implications are discussed in the article?

The article highlights the risks of remote code execution due to the zero-day vulnerability and the likelihood of state-sponsored attacks.

3

What products or software are affected by this vulnerability?

The affected products include Palo Alto Networks PAN-OS, PA-Series, and VM-Series firewalls.

4

When was the exploitation of this vulnerability first reported?

The exploitation of the PAN-OS zero-day vulnerability has been reported since April 9.

5

Who is suspected to be behind the exploitation of the vulnerability?

Suspected state-sponsored hackers are believed to be targeting the vulnerability for exploitation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203