Critical Buffer Overflow Vulnerability in Palo Alto Networks PAN-OS Software

the exploit blog logo
Penetration Testing Blog
Critical Buffer Overflow Vulnerability in Palo Alto Networks PAN-OS Software
Posted on May 13, 2026
Written by Andrew Trexler

Earlier this month a new vulnerability, CVE-2026-0300, was discovered in Palo Alto’s Authentication Portal. This vulnerability could allow an unauthenticated attacker to execute arbitrary code as the root user. 

If the authentication portal is only exposed to internal and trusted networks, the risk is reduced; however, any authentication portal exposed to the wider internet could allow an attacker to gain root access to the device.

Per Palo Alto this issue affects PA-Series and VM-Series firewalls with User-ID authentication Portal. Limited exploitation has been reported.

What to Do Now

Palo Alto Networks has released fixes in recent PAN-OS updates. They strongly recommend that all affected organizations implement them immediately. 

Andrew Trexler

Andrew Trexler

Andrew graduated from the University of Pittsburgh with a degree in Information Science where he focused on networking and security. He continued his education by obtaining the Offensive Security Certified Professional (OSCP) and the eLearnSecurity Junior Penetration Tester (eJPT) certifications. When not participating in capture the flag events, Andrew works as a pyrotechnic operator setting up and shooting firework shows in the Pittsburgh area.

About The Exploit Blog

The Exploit is written by Raxis penetration testers. Every post is a technical writeup from someone who runs engagements for a living, with code, command output, and the reasoning behind each step. Topics include exploit research, vulnerability disclosure, tool development, and the offensive techniques showing up in current client work.

Search The Exploit Blog

Raxis Discovered Vulnerabilities

View the CVEs and bugs that Raxis pentesters have uncovered and submitted.

Join Our Newsletter

Name(Required)
Newsletter(Required)
Do you wish to join our newsletter? We send out emails once a month that cover the latest in cybersecurity news. We do not sell your information to other parties.