CVE-2026-0300 Palo Alto Networks PAN-OS Buffer Overflow Overview & Takeaways
netspi.com | vulnerability | CVE-2026-0300 | #rce | #zero-day | #firewall | #pan-os | #palo-alto | #cve-2026-0300 | #in-the-wild
Summary
CVE-2026-0300 is a pre-auth buffer overflow in the PAN-OS User-ID Authentication Portal giving unauthenticated root RCE on PA-Series and VM-Series firewalls, already exploited in the wild.
- CVE
- CVE-2026-0300
- Published
- Collected
Related coverage
vulnerability ·
wiz.io
Critical Buffer Overflow Vulnerability in PAN-OS Exploited in-the-Wild
CVE-2026-0300: a buffer overflow in PAN-OS User-ID Authentication Portal (CVSS 9.3) allows unauthenticated root RCE, with limited in-the-wild exploitation of exposed instances; patching advised.
vulnerability ·
projectzero.google
Detection Deficit: A Year in Review of 0-days Used In-The-Wild in 2019
In May 2019, Project Zero released our tracking spreadsheet for 0-days used “in the wild” and we started a more focused effort on analyzing and learning from these exploits. This is another way Project Zero is trying to make zero-day hard. This blog post synthesizes many of our efforts and what we’ve seen over the last year. We provide a review of what we can learn from 0-day exploits detected as used in the wild in 2019. In conjunction with this blog post, we are also publishing another blog post today about our root cause analysis work that informed the conclusions in this Year in Review. We are also releasing 8 root cause analyses that we have done for in-the-wild 0-days from 2019.
vulnerability ·
projectzero.google
Root Cause Analyses for 0-day In-the-Wild Exploits
Our effort on this began in earnest in the last quarter of 2019. Today we are beginning to publish the root cause analyses for 0-days exploited in the wild that we have completed. While we’re publishing some in bulk now to play “catch-up”, in the future we plan to post each one in a timely manner after it’s detected and disclosed. We think publishing technical details in a timely manner is important for transparency and so that the whole of the security community can make informed decisions and actions.
vulnerability ·
projectzero.google
TFW you-get-really-excited-you-patch-diffed-a-0day-used-in-the-wild-but-then-find-out-it-is-the-wrong-vuln
I’m really interested in 0-days exploited in the wild and what we, the security community, can learn about them to make 0-day hard. I explained some of Project Zero’s ideas and goals around in-the-wild 0-days in a November blog post.
research ·
swarm.ptsecurity.com
Swarm of Palo Alto PAN-OS vulnerabilities
Analysis of four Palo Alto PAN-OS firewall vulnerabilities: authenticated command injection (CVE-2020-2037, CVE-2020-2038), unauthenticated denial of service (CVE-2020-2039) and reflected XSS (CVE-2020-2036) — each able to leak data, disrupt components or expose internal segments.
tool ·
github.com
Comment2Shell: Zero-Click Pre-Auth RCE Exploit Kit for WordPress (CVE-2026-93485)
Affects all WordPress installations from version 4.7.0 through 7.1.0 without requiring credentials or interaction beyond opening a post. Administrators should verify upgrading to 7.1.1 or backported releases, and monitor server logs for suspicious comment payloads and unexpected plugin uploads.
Skip to content