Palo Alto PAN-OS Captive Portal — unauthenticated root RCE (CVSS 9.3, ITW, KEV deadline 2026-05-09)
cve · CVE-2026-0300
Coverage timeline
3
first 2026-05-07 → last 2026-05-09
Briefs
3
3 distinct
Sources cited
7
6 hosts
Sections touched
2
active_vulns, updates
Co-occurring entities
0
no co-occurrence
Story timeline
- 2026-05-09CTI Daily Brief — 2026-05-09
- 2026-05-08CTI Daily Brief — 2026-05-08
- 2026-05-07CTI Daily Brief — 2026-05-07
Where this entity is cited
- updates2
- active_vulns1
Source distribution
- attack.mitre.org2 (29%)
- security.paloaltonetworks.com1 (14%)
- cert.europa.eu1 (14%)
- cert.ssi.gouv.fr1 (14%)
- cisa.gov1 (14%)
- unit42.paloaltonetworks.com1 (14%)
External references
All cited sources (7)
- security.paloaltonetworks.comprimaryfooterPalo Alto Security Advisory — CVE-2026-0300 update, 2026-05-08https://security.paloaltonetworks.com/CVE-2026-0300
- attack.mitre.orginlineEarthWormhttps://attack.mitre.org/techniques/T1090/
- attack.mitre.orginlineT1003 — OS Credential Dumpinghttps://attack.mitre.org/techniques/T1003/
- cert.europa.euinlineCERT-EU Advisory 2026-006, 2026-05-06https://cert.europa.eu/publications/security-advisories/2026-006/
- cert.ssi.gouv.frinlineCERT-FR CERTFR-2026-AVI-0537, 2026-05-06https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0537/
- cisa.govinlineCISA KEV cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalog
- unit42.paloaltonetworks.cominlineUnit 42, 2026-05-06https://unit42.paloaltonetworks.com/captive-portal-zero-day/