Critical PAN-OS flaw exploited against exposed firewalls

Palo Alto Networks has disclosed a critical vulnerability in PAN-OS, CVE-2026-0300, affecting the User-ID Authentication Portal, also known as the Captive Portal. It carries a CVSS score of 9.3 and may allow unauthenticated remote code execution with root privileges on affected PA-Series and VM-Series firewalls. The vendor confirms limited active exploitation against internet-exposed systems. Patches were not available at the time of the advisory.

What this means for your organisation

This is the combination that demands action the same day: no authentication, root privileges, internet exposure and confirmed exploitation. A compromised firewall gives an attacker both access to the inside and a view of how you have built your defence. That no patch exists yet does not mean you wait. It means compensating controls are the main measure right now.

Berigo recommends

  • Block access to the User-ID Authentication Portal from the internet and from untrusted networks, immediately.
  • Disable the feature entirely where it is not in use.
  • Review firewall logs for signs of exploitation before the mitigations were applied.
  • Activate the incident response plan as soon as you find anything unexpected, rather than investigating further on your own.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch