Palo Alto Firewall Buffer Overflow Grants Root RCE
Palo Alto firewalls have a buffer overflow attackers exploit for unauthenticated root RCE. They hit exposed User-ID portals with crafted packets.
CVE-2026-0300 sits in the User-ID Authentication Portal service. CVSS 9.3, limited active exploitation confirmed by Palo Alto.
PA-Series and VM-Series firewalls running PAN-OS 10.2 through 12.1 count as exposed if portals face the internet on ports 6081 or 6082.
Patches start rolling out May 13 with 12.1.4-h5 and others.
