Palo Alto Networks to Address Zero-Day Vulnerability in Firewalls
Palo Alto Networks is preparing to release patches for a critical zero-day vulnerability, CVE-2026-0300, affecting its PAN-OS software. The vulnerability, a buffer overflow in the User-ID Authentication Portal, allows unauthenticated attackers to execute code with root privileges. Limited exploitation has been observed, primarily targeting firewalls exposed to untrusted IPs. The company plans to release initial patches on May 13, with further updates by May 28. The flaw affects PA and VM series firewalls, but not Prisma Access, Cloud NGFW, or Panorama appliances.