boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Monday, October 5, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-0300

Palo Alto Networks Cloud NGFW — PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .3172   98.3   YES
AFFECTED
  Product        Versions     Fixed
  Cloud NGFW     unspecified  All
  PAN-OS         12.1.0 –     12.1.7
  Prisma Access  unspecified  All
TIMELINE
  Nov 3   Reserved by palo_alto
  May 6   Added to CISA KEV, remediation due 2026-05-09
  May 6   Published (CNA: palo_alto)
CWE-787 · CNA: palo_alto · CVSS v4.0 · 3 references · KEV due May 9, 2026

Description

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
November 3, 2025ReservedReserved by palo_alto
May 6, 2026KEV ADDEDAdded to CISA KEV, remediation due 2026-05-09
May 6, 2026PublishedPublished (CNA: palo_alto)

Affected

Affected products and packages — 3 rows
VendorProduct / PackageEcosystemVersion introducedFixed
Palo Alto NetworksCloud NGFW——All
Palo Alto NetworksPAN-OS—12.1.012.1.7
Palo Alto NetworksPrisma Access——All

Weaknesses

CWE-787

References (3)

Related

Authoritative record: CVE-2026-0300 at cve.org

Vendors: palo alto networks

Weaknesses: CWE-787

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-0300 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Monday, October 5, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.