Palo Alto Networks warned customers that suspected state-sponsored hackers have been exploiting a critical-severity PAN-OS firewall zero-day vulnerability for nearly a month. Tracked as CVE-2026-0300, this remote code execution security flaw was found in the PAN-OS User-ID Authentication Portal (also known as the Captive Portal) and stems from a buffer overflow vulnerability that allows unauthenticated attackers to execute arbitrary code with root privileges on Internet-exposed PA-Series and VM-Series firewalls. "We are aware of only limited exploitation of CVE-2026-0300 at this time. Unit 42 is tracking CL-STA-1132, a cluster of likely state-sponsored threat activity exploiting CVE-2026-0300. The attacker behind this activity exploited CVE-2026-0300 to achieve unauthenticated remote code execution (RCE) in PAN-OS software," the company said. "Starting April 9, 2026, there were unsuccessful exploitation attempts against a PAN-OS device. A week later, the attackers successfully achieved RCE against the device and injected shellcode. Following the compromise, the attackers immediately conducted log cleanup to mitigate detection by clearing crash kernel messages, deleting nginx crash entries and nginx crash records, as well as removing crash core dump files." After compromising the victims' firewalls, the attackers deployed the open-source Earthworm and ReverseSocks5network tunneling tools, which can be used to create SOCKS v5 servers and proxy tunnels on compromised devices, r...
Palo Alto Networks firewall zero-day exploited for nearly a month
BleepingComputer
·Sergiu Gatlan
·Published May 7, 2026
·Updated
Affected Software
3 affected components
Palo Alto Networks PAN-OS
Palo Alto Networks PA-Series
Palo Alto Networks VM-Series
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical-severity zero-day vulnerability in Palo Alto Networks' PAN-OS firewall that has been exploited by hackers.
2
What security implications are discussed in the article?
The article highlights the risks of remote code execution due to the zero-day vulnerability and the likelihood of state-sponsored attacks.
3
What products or software are affected by this vulnerability?
The affected products include Palo Alto Networks PAN-OS, PA-Series, and VM-Series firewalls.
4
When was the exploitation of this vulnerability first reported?
The exploitation of the PAN-OS zero-day vulnerability has been reported since April 9.
5
Who is suspected to be behind the exploitation of the vulnerability?
Suspected state-sponsored hackers are believed to be targeting the vulnerability for exploitation.