Threat reportZero-DayTL-2026-0465
PAN-OS User-ID Authentication Portal RCE Zero-Day (CVE-2026-0300) — Active Exploitation on PA-Series & VM-Series Firewalls
PAN-OS User-ID Authentication Portal RCE Zero-Day (TL-2026-0465), also tracked as PAN-SA-2026-0300, is a critical-severity zero-day vulnerability scored CVSS 10, first published 2026-05-06. It is attributed to CL-STA-1132 with medium confidence, affects Palo Alto Networks PAN-OS (PA-Series hardware firewalls), references 1 CVE (CVE-2026-0300), maps to 28 MITRE ATT&CK techniques (T1003, T1018, T1027), and is covered by 9 detection rules and 25 indicators of compromise.
- CVSS
- 10/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 28MITRE ATT&CK
- Actors
- 1CL-STA-1132
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 25Indicators of compromise
Key facts for TL-2026-0465
- Threat ID
- TL-2026-0465
- Also known as
- PAN-SA-2026-0300, Operation PortalSlip, Authentication Portal Zero-Day
- Severity
- CRITICAL
- CVSS
- 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- ZERO_DAY
- First published
- Last reviewed
- Attribution
- CL-STA-1132
- Attribution confidence
- MEDIUM
- Motivation
- espionage
- Target sectors
- government, financial, telecommunications, energy, healthcare, technology, defense, managed-service-providers
- Target regions
- Asia, North America, Europe
- Detection rules
- 9
- Indicators of compromise
- 25
Malware and tooling in PAN-OS User-ID Authentication Portal RCE Zero-Day
Malware and tooling: PORTALHIJACK, Cobalt Strike, Cobalt Strike 4.10 with custom Malleable C2 profile mimicking Palo Alto Networks update traffic
How PAN-OS User-ID Authentication Portal RCE Zero-Day works
Palo Alto Networks disclosed CVE-2026-0300, an unauthenticated stack buffer overflow in the PAN-OS User-ID Authentication Portal (Captive Portal) reachable via the data-plane HTTPS service that grants attackers root code execution on PA-Series and VM-Series next-generation firewalls. Limited but confirmed in-the-wild exploitation has been observed against Internet-exposed portals; Shadowserver tracks over 5,800 exposed VM-Series instances, the majority in Asia and North America. No patch is available; PAN-OS 11.2, 11.1, 11.0, 10.2 and 10.1 are all affected, and the only mitigations are restricting the Authentication Portal to trusted zones, disabling it entirely, or applying the published Threat Prevention signatures.
CVE-2026-0300 is a pre-authentication memory-corruption vulnerability in the User-ID Authentication Portal (also referred to as the Captive Portal / authd front-end) component of PAN-OS, the operating system that powers Palo Alto Networks PA-Series hardware and VM-Series virtual next-generation firewalls. The flaw resides in the HTTP request parsing routine that handles the Layer-7 redirection and form-based login pages served by the firewall when the Authentication Portal is enabled in a security policy. A specially crafted multi-part HTTP/HTTPS request to the portal endpoint causes a stack buffer overflow inside the userid-authd helper process, which runs with root privileges and is reachable on whichever data-plane interface the portal is bound to (frequently a Layer-3 interface facing untrusted users for Captive Portal workflows). Successful exploitation yields arbitrary code execution as root inside the management/data-plane control namespace of PAN-OS, allowing the attacker to read all firewall configuration including IPSec / GlobalProtect pre-shared keys and certificate private keys, modify rule bases, mint persistent credentials, pivot through site-to-site tunnels, and stage second-stage implants on the device.
Palo Alto Networks PSIRT confirmed limited active exploitation in the wild beginning in late April 2026 after telemetry partners and at least one large enterprise reported anomalous outbound shell-like traffic from Authentication Portal services. The attack chain observed in current campaigns proceeds in three stages: (1) reconnaissance scanning for /global-protect/portal/login.esp, /authentication/login.esp and /sslvpn/HwInit.esp endpoints to fingerprint Authentication Portal-enabled firewalls; (2) exploitation via a single oversized HTTP POST to the redirect parameter that triggers the overflow and pivots execution to a return-oriented-programming chain crafted against PAN-OS userland binaries; (3) deployment of a Bash dropper that writes a small ELF stager (PORTALHIJACK) to /opt/pancfg/runtime/portal/ and re-launches it under the legitimate panio process tree to blend with normal portal activity. The stager establishes outbound HTTPS C2 over TCP/443 using domain-fronting through legitimate CDN edges, pulls a second-stage Cobalt Strike beacon, exfiltrates running-config.xml plus panrc credentials, and clears /var/log/cms.log, /var/log/wf-monitor.log and the authd portal access log to remove evidence.
No patched PAN-OS image is available at the time of disclosure. Palo Alto Networks has released Threat Prevention signature 95720 (and follow-on signatures 95721/95722 for variants) as a virtual patch when the firewall has Threat Prevention licensed and SSL inbound inspection enabled for the portal interface. Vendor guidance prioritises (a) confirming whether the Authentication Portal is enabled and which interfaces serve it, (b) restricting access to internal trusted zones using the dedicated Authentication Portal interface zoning, (c) temporarily disabling the Authentication Portal entirely where business workflow allows, and (d) ensuring Threat Prevention with the new signatures is applied. CISA is expected to add CVE-2026-0300 to the Known Exploited Vulnerabilities catalogue with a 14-day federal remediation deadline. Defenders should treat any Internet-exposed PAN-OS firewall with the Authentication Portal enabled as potentially compromised until forensic triage of the configuration, log files, and management plane processes is complete.
MITRE ATT&CK techniques used in TL-2026-0465
Credential Access
T1003 OS Credential Dumping; T1552.001 Unsecured Credentials: Credentials In Files
Discovery
T1018 Remote System Discovery; T1083 File and Directory Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1070.004 Indicator Removal: File Deletion
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059 Command and Scripting Interpreter; T1059.004 Unix Shell
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1090.004 Proxy: Domain Fronting; T1572 Protocol Tunneling; T1573.002 Encrypted Channel: Asymmetric Cryptography
Initial Access
T1133 External Remote Services; T1190 Exploit Public-Facing Application
Impact
T1498 Network Denial of Service
Persistence
T1505.003 Server Software Component: Web Shell; T1543 Create or Modify System Process
Lateral Movement
T1534 Internal Spearphishing; T1550 Use Alternate Authentication Material
Resource Development
T1583 Acquire Infrastructure; T1608 Stage Capabilities
Reconnaissance
T1595 Active Scanning; T1595.002 Vulnerability Scanning
Collection
T1602 Data from Configuration Repository
defense-impairment
T1685 Disable or Modify Tools; T1685.006 Clear Linux or Mac System Logs
Affected products and versions in PAN-OS User-ID Authentication Portal RCE Zero-Day
- Palo Alto Networks — PAN-OS (PA-Series hardware firewalls)
Vulnerable versions: 11.2.0 through 11.2.4; 11.1.0 through 11.1.7; 11.0.0 through 11.0.10; 10.2.0 through 10.2.13; 10.1.0 through 10.1.16
Fixed in: 11.2.5-h1 (pending); 11.1.7-h2 (pending); 11.0.10-h3 (pending); 10.2.13-h4 (pending); 10.1.16-h5 (pending) - Palo Alto Networks — PAN-OS (VM-Series virtual firewalls)
Vulnerable versions: 11.2.0 through 11.2.4; 11.1.0 through 11.1.7; 11.0.0 through 11.0.10; 10.2.0 through 10.2.13; 10.1.0 through 10.1.16
Fixed in: 11.2.5-h1 (pending); 11.1.7-h2 (pending); 11.0.10-h3 (pending); 10.2.13-h4 (pending); 10.1.16-h5 (pending) - Palo Alto Networks — Prisma Access (customer-managed Authentication Portal)
Vulnerable versions: Customer-managed Prisma Access tenants using Authentication Portal feature
Fixed in: Vendor-managed mitigation rolled out 2026-05-05; customer-managed instances follow PAN-OS schedule
Remediation for PAN-OS User-ID Authentication Portal RCE Zero-Day
Patches
- No fixed PAN-OS image available at disclosure (2026-05-06). Palo Alto Networks has committed to releasing PAN-OS 11.2.5-h1, 11.1.7-h2, 11.0.10-h3, 10.2.13-h4 and 10.1.16-h5 as the first fixed images. Monitor https://security.paloaltonetworks.com/CVE-2026-0300 for release timing.
- Apply Threat Prevention content release 8911-9301 or later, which contains signatures 95720, 95721 and 95722 covering known exploit variants
Immediate actions
- Identify all firewalls with the Authentication Portal enabled: run 'show running authentication-portal' and 'show user authentication-portal' across the fleet via Panorama
- Restrict the Authentication Portal interface to trusted internal zones only; remove it from any Internet-facing or untrusted-zone interface
- Where business workflow permits, disable the Authentication Portal entirely until a fixed PAN-OS image is released
- Block source IPs 45.155.205.106, 91.92.245.182, 194.165.16.77, 167.71.224.115 and 23.95.89.214 at upstream filtering points
- Block DNS resolution for panupdate-cdn[.]com, pan-osupdate[.]net and update-paloalto[.]xyz
- Apply Threat Prevention signatures 95720, 95721 and 95722 with the action set to reset-both on all portal-serving interfaces
- Capture a forensic snapshot (tech-support file plus running-config plus management-plane process listing) before any remediation if compromise is suspected
Workarounds
- Disable the Authentication Portal in the rulebase or remove the portal interface from the network configuration entirely
- Restrict the portal to trusted zones using a dedicated source-zone match in the Authentication policy and remove any any-source-zone references
- Add an Authentication Portal-specific Security policy that allows access only from internal user subnets and denies all other traffic
- If portal access from the Internet is unavoidable, place the firewall behind an upstream WAF or reverse proxy that can enforce request size limits below the overflow threshold (observed at >8192 bytes in the redirect parameter)
Longer-term hardening
- Deploy out-of-band management for all Palo Alto Networks firewalls so that User-ID, Authentication Portal and management interfaces are never exposed to untrusted networks
- Enable SSL Inbound Inspection on Authentication Portal interfaces so future Threat Prevention signatures can decrypt and inspect portal payloads
- Forward all PAN-OS system, traffic, threat and authd logs to an external SIEM with retention of at least 365 days and immutable storage
- Implement automated configuration drift detection (eg. via Panorama API or Expedition) so unauthorised changes to portal settings or admin accounts are flagged within minutes
- Subscribe Authentication Portal-serving firewalls to Advanced Threat Prevention for inline ML-based detection of anomalous portal traffic
CVEs associated with PAN-OS User-ID Authentication Portal RCE Zero-Day
Weaknesses (CWE) in PAN-OS User-ID Authentication Portal RCE Zero-Day
Timeline of PAN-OS User-ID Authentication Portal RCE Zero-Day
- Earliest known exploitation telemetry: anomalous outbound HTTPS beacons from PAN-OS authd processes observed by a North American financial services CSIRT
- Asian telecommunications provider reports unauthorized configuration changes on Internet-facing VM-Series firewalls and forwards artefacts to PAN PSIRT
- Palo Alto Networks PSIRT triages reports and confirms a reproducible stack buffer overflow in the Authentication Portal HTTP request parser
- PAN-OS engineering reproduces unauthenticated root code execution via crafted POST to portal endpoint; CVE-2026-0300 reserved with MITRE
- Multiple incident response firms (Volexity, Mandiant, Unit 42) corroborate active exploitation against government and managed-service-provider targets in three regions
- Palo Alto Networks rolls out vendor-side mitigation for cloud-managed Prisma Access tenants and stages Threat Prevention signatures 95720/95721/95722
- Palo Alto Networks commits to first fixed PAN-OS images (11.2.5-h1, 11.1.7-h2, 11.0.10-h3, 10.2.13-h4, 10.1.16-h5); release timing pending QA
- CISA issues Alert AA26-126A and signals imminent KEV listing with a 14-day federal remediation deadline
- Public advisory PAN-SA-2026-0300 published; BleepingComputer, Unit 42 and Shadowserver report; ~5,800 exposed VM-Series instances catalogued
- As of 2026-05-29, CVE-2026-0300 remains a live threat: it is in CISA KEV and the PAN vendor advisory still marks exploit maturity "ATTACKED" with ongoing in-the-wild root RCE against internet-exposed PAN-OS Authentication Portals. Fixed images shipped May 13-28, 2026, but exploitation continues and the ~5,800 exposed instances are not all patched.
Sources cited for PAN-OS User-ID Authentication Portal RCE Zero-Day
- Palo Alto Networks warns of firewall RCE zero-day exploited in attacks
- PAN-SA-2026-0300: Authentication Portal Stack Buffer Overflow (CVE-2026-0300)
- CVE-2026-0300 — NVD
- Unit 42 Threat Brief: Active Exploitation of PAN-OS Authentication Portal
- Shadowserver Dashboard — Exposed PAN-OS Authentication Portals
- CISA Alert AA26-126A: Active Exploitation of CVE-2026-0300 in PAN-OS
- Volexity: Initial Analysis of PORTALHIJACK Implant Deployed via CVE-2026-0300
- Mandiant: Tracking In-the-Wild Exploitation of PAN-OS Authentication Portal
- Palo Alto Networks Live Community — CVE-2026-0300 Mitigation Workflow
- Threat Prevention Content Release 8911-9301 (signatures 95720/95721/95722)
Detection coverage for TL-2026-0465
As of 2026-05-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0465 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.