Skip to main content
See every side of every news story
Published loading...Updated

State-Backed Hackers Hammer Palo Alto Firewall Zero-Day Before Patch Lands

Palo Alto Networks says the flaw allows unauthenticated attackers to run code as root on internet-exposed firewalls, and Shadowserver is tracking over 5,800 exposed devices.

  • Palo Alto Networks warned on Wednesday that a critical-severity unpatched vulnerability, CVE-2026-0300, is being exploited in attacks targeting the PAN-OS User-ID Authentication Portal.
  • The zero-day bug stems from a buffer overflow weakness allowing unauthenticated attackers to execute arbitrary code with root privileges on Internet-exposed PA-Series and VM-Series firewalls via specially crafted packets.
  • Internet threat watchdog Shadowserver is tracking over 5,800 PAN-OS VM-series firewalls exposed online, with 2,466 located in Asia and 1,998 in North America.
  • Palo Alto Networks is working on a patch and until available, "strongly" recommends customers secure the User-ID Authentication Portal by restricting access to trusted zones only or disabling it.
  • "Customers following standard security best practices, such as restricting sensitive portals to trusted internal networks are at a greatly reduced risk," the company stated regarding exposure mitigation.
Insights by Ground AI
Podcasts & Opinions

17 Articles

Palo Alto Networks confirms that the critical vulnerability CVE-2026-0300 (CVSS 9.3) in PAN-OS is under active attack, allowing remote execution of code without authentication. The company has issued an urgent warning after detecting actual exploitation, mainly against firewalls PA-Series and VM-Series with the User-ID authentication portal exposed to the Internet. Patches will not arrive until May 13 — as soon as possible — and, meanwhile, any …

Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

securityweek.com broke the news on Wednesday, May 6, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal