Critical PAN-OS Flaw Under Active Exploitation Enabling Root RCE

1 min read
Source: The Hacker News
Critical PAN-OS Flaw Under Active Exploitation Enabling Root RCE
Photo: The Hacker News
TL;DR Summary

Palo Alto Networks warns of a critical buffer‑overflow flaw in PAN-OS User-ID Authentication Portal (CVE-2026-0300) that allows unauthenticated remote code execution with root privileges on PA-Series and VM-Series firewalls; the bug is under active exploitation, with a CVSS of up to 9.3 when the portal is internet‑exposed and 8.7 otherwise, and PAN-OS 12.1 is listed as affected.

Share this article

Reading Insights

Total Reads

1

Unique Readers

3

Time Saved

4 min

vs 4 min read

Condensed

93%

76457 words

Want the full story? Read the original article

Read on The Hacker News