Palo Alto Networks Discloses CVE-2026-0300, a 9.3 PAN-OS Captive Portal RCE Exploited Since April 9 With Patches Starting May 13
Palo Alto Networks disclosed CVE-2026-0300, a critical buffer overflow in PAN-OS that grants unauthenticated root code execution and has been exploited in the wild since April 9. CISA added it to KEV on May 6 with a May 9 federal deadline; first fixes ship May 13.
4 min read6 sources