Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

OpenAI is reportedly preparing legal action against Apple. This isn’t the first time my partner has been burned.

Clawdmeter turns your Clawd code usage statistics into a small desktop dashboard

Cisco Catalyst SD-WAN Controller Authentication Bypass Is Actively Abused to Gain Administrative Access

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Palo Alto PAN-OS vulnerability exploited to allow remote code execution
Identity

Palo Alto PAN-OS vulnerability exploited to allow remote code execution

By May 6, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananMay 6, 2026Vulnerability/Network Security

Palo Alto PAN-OS defect

Palo Alto Networks has issued an advisory warning that a critical buffer overflow vulnerability in PAN-OS software is being exploited in the wild.

This vulnerability is tracked as CVE-2026-0300 and is described as a case of unauthenticated remote code execution. If the User Identity Authentication Portal is configured to allow access from the Internet or untrusted networks, the CVSS score will be 9.3. If access to the portal is restricted to trusted internal IP addresses only, the severity is 8.7.

“A buffer overflow vulnerability in the User-ID Authentication Portal (also known as Captive Portal) service in Palo Alto Networks’ PAN-OS software could allow an unauthenticated attacker to execute arbitrary code with root privileges on PA Series and VM Series firewalls by sending specially crafted packets,” the company said.

According to Palo Alto Networks, the vulnerability has been used in “limited exploitation,” specifically targeting instances where the User-ID authentication portal has been left exposed. The following versions are affected by this flaw:

PAN-OS 12.1 – < 12.1.4-h5, < 12.1.7 PAN-OS 11.2 - < 11.2.4-h17, < 11.2.7-h13, < 11.2.10-h6, < 11.2.12 PAN-OS 11.1 - < 11.1.4-h33, < 11.1.6-h32, < 11.1.7-h6, < 11.1.10-h25, < 11.1.13-h5, < 11.1.15 PAN-OS 10.2 - < 10.2.7-h34, < 10.2.10-h36, < 10.2.13-h21, < 10.2.16-h7, < 10.2.18-h6

This issue is currently unpatched and Palo Alto Networks plans to release a fix starting May 13, 2026. The company also said the vulnerability only applies to PA-series and VM-series firewalls that are configured to use the User-ID authentication portal.

“Customers who follow standard security best practices, such as restricting sensitive portals to trusted internal networks, have significantly reduced risk,” it added.

If unpatched, users are encouraged to limit access to the User-ID Authentication Portal to trusted zones only, or disable it completely if it is not needed.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleBumble’s number of paying users is on the decline as they bet on overhaul later this year
Next Article European Processor Initiative finishes second stage

Related Posts

Cisco Catalyst SD-WAN Controller Authentication Bypass Is Actively Abused to Gain Administrative Access

May 14, 2026

Stealer backdoor targeting developer secrets found in three node IPC versions

May 14, 2026

PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ Stories

May 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

OpenAI is reportedly preparing legal action against Apple. This isn’t the first time my partner has been burned.

Clawdmeter turns your Clawd code usage statistics into a small desktop dashboard

Cisco Catalyst SD-WAN Controller Authentication Bypass Is Actively Abused to Gain Administrative Access

Stealer backdoor targeting developer secrets found in three node IPC versions

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.