CVE-2026-0300
Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
⚠ KEVEPSS 4.5%
Description
Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.
How to fix CVE-2026-0300
No package mapping is available — consult the references below for vendor-specific guidance.
Is CVE-2026-0300 being exploited?
Yes — CVE-2026-0300 is on the CISA Known Exploited Vulnerabilities (KEV) catalog. Patch immediately.
Affected packages (0)
No package mapping in OSV.