# PAN-OS User-ID Authentication Portal RCE Zero-Day (CVE-2026-0300) — Active Exploitation on PA-Series & VM-Series Firewalls

> Palo Alto Networks disclosed CVE-2026-0300, an unauthenticated stack buffer overflow in the PAN-OS User-ID Authentication Portal (Captive Portal) reachable via the data-plane HTTPS service that grants attackers root code execution on PA-Series and VM-Series next-generation firewalls. Limited but confirmed in-the-wild exploitation has been observed against Internet-exposed portals; Shadowserver tracks over 5,800 exposed VM-Series instances, the majority in Asia and North America. No patch is available; PAN-OS 11.2, 11.1, 11.0, 10.2 and 10.1 are all affected, and the only mitigations are restricting the Authentication Portal to trusted zones, disabling it entirely, or applying the published Threat Prevention signatures.

- **Published:** 2026-05-06T12:00:00Z
- **Last reviewed:** 2026-05-06T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0465
- **ID:** TL-2026-0465
- **Severity:** CRITICAL (CVSS 10)
- **Category:** ZERO_DAY
- **Status:** ACTIVE
- **Actor:** CL-STA-1132
- **Detections:** 9 · **IOCs:** 25 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-0300

## Description

CVE-2026-0300 is a pre-authentication memory-corruption vulnerability in the User-ID Authentication Portal (also referred to as the Captive Portal / authd front-end) component of PAN-OS, the operating system that powers Palo Alto Networks PA-Series hardware and VM-Series virtual next-generation firewalls. The flaw resides in the HTTP request parsing routine that handles the Layer-7 redirection and form-based login pages served by the firewall when the Authentication Portal is enabled in a security policy. A specially crafted multi-part HTTP/HTTPS request to the portal endpoint causes a stack buffer overflow inside the userid-authd helper process, which runs with root privileges and is reachable on whichever data-plane interface the portal is bound to (frequently a Layer-3 interface facing untrusted users for Captive Portal workflows). Successful exploitation yields arbitrary code execution as root inside the management/data-plane control namespace of PAN-OS, allowing the attacker to read all firewall configuration including IPSec / GlobalProtect pre-shared keys and certificate private keys, modify rule bases, mint persistent credentials, pivot through site-to-site tunnels, and stage second-stage implants on the device.

Palo Alto Networks PSIRT confirmed limited active exploitation in the wild beginning in late April 2026 after telemetry partners and at least one large enterprise reported anomalous outbound shell-like traffic from Authentication Portal services. The attack chain observed in current campaigns proceeds in three stages: (1) reconnaissance scanning for /global-protect/portal/login.esp, /authentication/login.esp and /sslvpn/HwInit.esp endpoints to fingerprint Authentication Portal-enabled firewalls; (2) exploitation via a single oversized HTTP POST to the redirect parameter that triggers the overflow and pivots execution to a return-oriented-programming chain crafted against PAN-OS userland binaries; (3) deployment of a Bash dropper that writes a small ELF stager (PORTALHIJACK) to /opt/pancfg/runtime/portal/ and re-launches it under the legitimate panio process tree to blend with normal portal activity. The stager establishes outbound HTTPS C2 over TCP/443 using domain-fronting through legitimate CDN edges, pulls a second-stage Cobalt Strike beacon, exfiltrates running-config.xml plus panrc credentials, and clears /var/log/cms.log, /var/log/wf-monitor.log and the authd portal access log to remove evidence.

No patched PAN-OS image is available at the time of disclosure. Palo Alto Networks has released Threat Prevention signature 95720 (and follow-on signatures 95721/95722 for variants) as a virtual patch when the firewall has Threat Prevention licensed and SSL inbound inspection enabled for the portal interface. Vendor guidance prioritises (a) confirming whether the Authentication Portal is enabled and which interfaces serve it, (b) restricting access to internal trusted zones using the dedicated Authentication Portal interface zoning, (c) temporarily disabling the Authentication Portal entirely where business workflow allows, and (d) ensuring Threat Prevention with the new signatures is applied. CISA is expected to add CVE-2026-0300 to the Known Exploited Vulnerabilities catalogue with a 14-day federal remediation deadline. Defenders should treat any Internet-exposed PAN-OS firewall with the Authentication Portal enabled as potentially compromised until forensic triage of the configuration, log files, and management plane processes is complete.

## MITRE ATT&CK

- T1595 Active Scanning
- T1595.002 Vulnerability Scanning
- T1583 Acquire Infrastructure
- T1608 Stage Capabilities
- T1190 Exploit Public-Facing Application
- T1133 External Remote Services
- T1059 Command and Scripting Interpreter
- T1059.004 Unix Shell
- T1505.003 Server Software Component: Web Shell
- T1543 Create or Modify System Process
- T1068 Exploitation for Privilege Escalation
- T1027 Obfuscated Files or Information
- T1070.004 Indicator Removal: File Deletion
- T1685.006 Clear Linux or Mac System Logs
- T1685 Disable or Modify Tools
- T1552.001 Unsecured Credentials: Credentials In Files
- T1003 OS Credential Dumping
- T1083 File and Directory Discovery
- T1018 Remote System Discovery
- T1550 Use Alternate Authentication Material
- T1534 Internal Spearphishing
- T1602 Data from Configuration Repository
- T1071.001 Application Layer Protocol: Web Protocols
- T1573.002 Encrypted Channel: Asymmetric Cryptography
- T1572 Protocol Tunneling
- T1090.004 Proxy: Domain Fronting
- T1041 Exfiltration Over C2 Channel
- T1498 Network Denial of Service

## Sources

- [Palo Alto Networks warns of firewall RCE zero-day exploited in attacks](https://www.bleepingcomputer.com/news/security/palo-alto-networks-warns-of-actively-exploited-firewall-zero-day/)
- [PAN-SA-2026-0300: Authentication Portal Stack Buffer Overflow (CVE-2026-0300)](https://security.paloaltonetworks.com/CVE-2026-0300)
- [CVE-2026-0300 — NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-0300)
- [Unit 42 Threat Brief: Active Exploitation of PAN-OS Authentication Portal](https://unit42.paloaltonetworks.com/cve-2026-0300-authentication-portal/)
- [Shadowserver Dashboard — Exposed PAN-OS Authentication Portals](https://dashboard.shadowserver.org/statistics/combined/map/?dataset=panos_portal)
- [CISA Alert AA26-126A: Active Exploitation of CVE-2026-0300 in PAN-OS](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-126a)
- [Volexity: Initial Analysis of PORTALHIJACK Implant Deployed via CVE-2026-0300](https://www.volexity.com/blog/2026/05/06/portalhijack-pan-os-zero-day/)
- [Mandiant: Tracking In-the-Wild Exploitation of PAN-OS Authentication Portal](https://cloud.google.com/blog/topics/threat-intelligence/cve-2026-0300-pan-os-portal)
- [Palo Alto Networks Live Community — CVE-2026-0300 Mitigation Workflow](https://live.paloaltonetworks.com/t5/community-blogs/cve-2026-0300/ba-p/600300)
- [Threat Prevention Content Release 8911-9301 (signatures 95720/95721/95722)](https://security.paloaltonetworks.com/threat-prevention/8911-9301)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0465
