Threat reportZero-DayTL-2026-0465

PAN-OS User-ID Authentication Portal RCE Zero-Day (CVE-2026-0300) — Active Exploitation on PA-Series & VM-Series Firewalls

criticalACTIVE

PAN-OS User-ID Authentication Portal RCE Zero-Day (TL-2026-0465), also tracked as PAN-SA-2026-0300, is a critical-severity zero-day vulnerability scored CVSS 10, first published 2026-05-06. It is attributed to CL-STA-1132 with medium confidence, affects Palo Alto Networks PAN-OS (PA-Series hardware firewalls), references 1 CVE (CVE-2026-0300), maps to 28 MITRE ATT&CK techniques (T1003, T1018, T1027), and is covered by 9 detection rules and 25 indicators of compromise.

CVSS
10/10Critical
CVEs
1Referenced vulnerabilities
Techniques
28MITRE ATT&CK
Actors
1CL-STA-1132
Detection rules
9SPL · KQL · Sigma
IOCs
25Indicators of compromise

Key facts for TL-2026-0465

Threat ID
TL-2026-0465
Also known as
PAN-SA-2026-0300, Operation PortalSlip, Authentication Portal Zero-Day
Severity
CRITICAL
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Status
ACTIVE
Category
ZERO_DAY
First published
Last reviewed
Attribution
CL-STA-1132
Attribution confidence
MEDIUM
Motivation
espionage
Target sectors
government, financial, telecommunications, energy, healthcare, technology, defense, managed-service-providers
Target regions
Asia, North America, Europe
Detection rules
9
Indicators of compromise
25

Malware and tooling in PAN-OS User-ID Authentication Portal RCE Zero-Day

Malware and tooling: PORTALHIJACK, Cobalt Strike, Cobalt Strike 4.10 with custom Malleable C2 profile mimicking Palo Alto Networks update traffic

How PAN-OS User-ID Authentication Portal RCE Zero-Day works

Palo Alto Networks disclosed CVE-2026-0300, an unauthenticated stack buffer overflow in the PAN-OS User-ID Authentication Portal (Captive Portal) reachable via the data-plane HTTPS service that grants attackers root code execution on PA-Series and VM-Series next-generation firewalls. Limited but confirmed in-the-wild exploitation has been observed against Internet-exposed portals; Shadowserver tracks over 5,800 exposed VM-Series instances, the majority in Asia and North America. No patch is available; PAN-OS 11.2, 11.1, 11.0, 10.2 and 10.1 are all affected, and the only mitigations are restricting the Authentication Portal to trusted zones, disabling it entirely, or applying the published Threat Prevention signatures.

CVE-2026-0300 is a pre-authentication memory-corruption vulnerability in the User-ID Authentication Portal (also referred to as the Captive Portal / authd front-end) component of PAN-OS, the operating system that powers Palo Alto Networks PA-Series hardware and VM-Series virtual next-generation firewalls. The flaw resides in the HTTP request parsing routine that handles the Layer-7 redirection and form-based login pages served by the firewall when the Authentication Portal is enabled in a security policy. A specially crafted multi-part HTTP/HTTPS request to the portal endpoint causes a stack buffer overflow inside the userid-authd helper process, which runs with root privileges and is reachable on whichever data-plane interface the portal is bound to (frequently a Layer-3 interface facing untrusted users for Captive Portal workflows). Successful exploitation yields arbitrary code execution as root inside the management/data-plane control namespace of PAN-OS, allowing the attacker to read all firewall configuration including IPSec / GlobalProtect pre-shared keys and certificate private keys, modify rule bases, mint persistent credentials, pivot through site-to-site tunnels, and stage second-stage implants on the device.

Palo Alto Networks PSIRT confirmed limited active exploitation in the wild beginning in late April 2026 after telemetry partners and at least one large enterprise reported anomalous outbound shell-like traffic from Authentication Portal services. The attack chain observed in current campaigns proceeds in three stages: (1) reconnaissance scanning for /global-protect/portal/login.esp, /authentication/login.esp and /sslvpn/HwInit.esp endpoints to fingerprint Authentication Portal-enabled firewalls; (2) exploitation via a single oversized HTTP POST to the redirect parameter that triggers the overflow and pivots execution to a return-oriented-programming chain crafted against PAN-OS userland binaries; (3) deployment of a Bash dropper that writes a small ELF stager (PORTALHIJACK) to /opt/pancfg/runtime/portal/ and re-launches it under the legitimate panio process tree to blend with normal portal activity. The stager establishes outbound HTTPS C2 over TCP/443 using domain-fronting through legitimate CDN edges, pulls a second-stage Cobalt Strike beacon, exfiltrates running-config.xml plus panrc credentials, and clears /var/log/cms.log, /var/log/wf-monitor.log and the authd portal access log to remove evidence.

No patched PAN-OS image is available at the time of disclosure. Palo Alto Networks has released Threat Prevention signature 95720 (and follow-on signatures 95721/95722 for variants) as a virtual patch when the firewall has Threat Prevention licensed and SSL inbound inspection enabled for the portal interface. Vendor guidance prioritises (a) confirming whether the Authentication Portal is enabled and which interfaces serve it, (b) restricting access to internal trusted zones using the dedicated Authentication Portal interface zoning, (c) temporarily disabling the Authentication Portal entirely where business workflow allows, and (d) ensuring Threat Prevention with the new signatures is applied. CISA is expected to add CVE-2026-0300 to the Known Exploited Vulnerabilities catalogue with a 14-day federal remediation deadline. Defenders should treat any Internet-exposed PAN-OS firewall with the Authentication Portal enabled as potentially compromised until forensic triage of the configuration, log files, and management plane processes is complete.

MITRE ATT&CK techniques used in TL-2026-0465

Credential Access

T1003 OS Credential Dumping; T1552.001 Unsecured Credentials: Credentials In Files

Discovery

T1018 Remote System Discovery; T1083 File and Directory Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1070.004 Indicator Removal: File Deletion

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059 Command and Scripting Interpreter; T1059.004 Unix Shell

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1090.004 Proxy: Domain Fronting; T1572 Protocol Tunneling; T1573.002 Encrypted Channel: Asymmetric Cryptography

Initial Access

T1133 External Remote Services; T1190 Exploit Public-Facing Application

Impact

T1498 Network Denial of Service

Persistence

T1505.003 Server Software Component: Web Shell; T1543 Create or Modify System Process

Lateral Movement

T1534 Internal Spearphishing; T1550 Use Alternate Authentication Material

Resource Development

T1583 Acquire Infrastructure; T1608 Stage Capabilities

Reconnaissance

T1595 Active Scanning; T1595.002 Vulnerability Scanning

Collection

T1602 Data from Configuration Repository

defense-impairment

T1685 Disable or Modify Tools; T1685.006 Clear Linux or Mac System Logs

Affected products and versions in PAN-OS User-ID Authentication Portal RCE Zero-Day

  • Palo Alto Networks — PAN-OS (PA-Series hardware firewalls)
    Vulnerable versions: 11.2.0 through 11.2.4; 11.1.0 through 11.1.7; 11.0.0 through 11.0.10; 10.2.0 through 10.2.13; 10.1.0 through 10.1.16
    Fixed in: 11.2.5-h1 (pending); 11.1.7-h2 (pending); 11.0.10-h3 (pending); 10.2.13-h4 (pending); 10.1.16-h5 (pending)
  • Palo Alto Networks — PAN-OS (VM-Series virtual firewalls)
    Vulnerable versions: 11.2.0 through 11.2.4; 11.1.0 through 11.1.7; 11.0.0 through 11.0.10; 10.2.0 through 10.2.13; 10.1.0 through 10.1.16
    Fixed in: 11.2.5-h1 (pending); 11.1.7-h2 (pending); 11.0.10-h3 (pending); 10.2.13-h4 (pending); 10.1.16-h5 (pending)
  • Palo Alto Networks — Prisma Access (customer-managed Authentication Portal)
    Vulnerable versions: Customer-managed Prisma Access tenants using Authentication Portal feature
    Fixed in: Vendor-managed mitigation rolled out 2026-05-05; customer-managed instances follow PAN-OS schedule

Remediation for PAN-OS User-ID Authentication Portal RCE Zero-Day

Patches

  • No fixed PAN-OS image available at disclosure (2026-05-06). Palo Alto Networks has committed to releasing PAN-OS 11.2.5-h1, 11.1.7-h2, 11.0.10-h3, 10.2.13-h4 and 10.1.16-h5 as the first fixed images. Monitor https://security.paloaltonetworks.com/CVE-2026-0300 for release timing.
  • Apply Threat Prevention content release 8911-9301 or later, which contains signatures 95720, 95721 and 95722 covering known exploit variants

Immediate actions

  • Identify all firewalls with the Authentication Portal enabled: run 'show running authentication-portal' and 'show user authentication-portal' across the fleet via Panorama
  • Restrict the Authentication Portal interface to trusted internal zones only; remove it from any Internet-facing or untrusted-zone interface
  • Where business workflow permits, disable the Authentication Portal entirely until a fixed PAN-OS image is released
  • Block source IPs 45.155.205.106, 91.92.245.182, 194.165.16.77, 167.71.224.115 and 23.95.89.214 at upstream filtering points
  • Block DNS resolution for panupdate-cdn[.]com, pan-osupdate[.]net and update-paloalto[.]xyz
  • Apply Threat Prevention signatures 95720, 95721 and 95722 with the action set to reset-both on all portal-serving interfaces
  • Capture a forensic snapshot (tech-support file plus running-config plus management-plane process listing) before any remediation if compromise is suspected

Workarounds

  • Disable the Authentication Portal in the rulebase or remove the portal interface from the network configuration entirely
  • Restrict the portal to trusted zones using a dedicated source-zone match in the Authentication policy and remove any any-source-zone references
  • Add an Authentication Portal-specific Security policy that allows access only from internal user subnets and denies all other traffic
  • If portal access from the Internet is unavoidable, place the firewall behind an upstream WAF or reverse proxy that can enforce request size limits below the overflow threshold (observed at >8192 bytes in the redirect parameter)

Longer-term hardening

  • Deploy out-of-band management for all Palo Alto Networks firewalls so that User-ID, Authentication Portal and management interfaces are never exposed to untrusted networks
  • Enable SSL Inbound Inspection on Authentication Portal interfaces so future Threat Prevention signatures can decrypt and inspect portal payloads
  • Forward all PAN-OS system, traffic, threat and authd logs to an external SIEM with retention of at least 365 days and immutable storage
  • Implement automated configuration drift detection (eg. via Panorama API or Expedition) so unauthorised changes to portal settings or admin accounts are flagged within minutes
  • Subscribe Authentication Portal-serving firewalls to Advanced Threat Prevention for inline ML-based detection of anomalous portal traffic

CVEs associated with PAN-OS User-ID Authentication Portal RCE Zero-Day

CVE-2026-0300

Weaknesses (CWE) in PAN-OS User-ID Authentication Portal RCE Zero-Day

CWE-120, CWE-121, CWE-787, CWE-119

Timeline of PAN-OS User-ID Authentication Portal RCE Zero-Day

  • Earliest known exploitation telemetry: anomalous outbound HTTPS beacons from PAN-OS authd processes observed by a North American financial services CSIRT
  • Asian telecommunications provider reports unauthorized configuration changes on Internet-facing VM-Series firewalls and forwards artefacts to PAN PSIRT
  • Palo Alto Networks PSIRT triages reports and confirms a reproducible stack buffer overflow in the Authentication Portal HTTP request parser
  • PAN-OS engineering reproduces unauthenticated root code execution via crafted POST to portal endpoint; CVE-2026-0300 reserved with MITRE
  • Multiple incident response firms (Volexity, Mandiant, Unit 42) corroborate active exploitation against government and managed-service-provider targets in three regions
  • Palo Alto Networks rolls out vendor-side mitigation for cloud-managed Prisma Access tenants and stages Threat Prevention signatures 95720/95721/95722
  • Palo Alto Networks commits to first fixed PAN-OS images (11.2.5-h1, 11.1.7-h2, 11.0.10-h3, 10.2.13-h4, 10.1.16-h5); release timing pending QA
  • CISA issues Alert AA26-126A and signals imminent KEV listing with a 14-day federal remediation deadline
  • Public advisory PAN-SA-2026-0300 published; BleepingComputer, Unit 42 and Shadowserver report; ~5,800 exposed VM-Series instances catalogued
  • As of 2026-05-29, CVE-2026-0300 remains a live threat: it is in CISA KEV and the PAN vendor advisory still marks exploit maturity "ATTACKED" with ongoing in-the-wild root RCE against internet-exposed PAN-OS Authentication Portals. Fixed images shipped May 13-28, 2026, but exploitation continues and the ~5,800 exposed instances are not all patched.

Sources cited for PAN-OS User-ID Authentication Portal RCE Zero-Day

Detection coverage for TL-2026-0465

As of 2026-05-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0465 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
25 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats