---
schema: 1
kind: threat
title: "CVE-2026-0300 — Palo Alto PAN-OS Captive Portal KEV deadline TODAY (2026-05-09); no patch exists; first patches expected 2026-05-13; CL-STA-1132 post-exploitation detail"
headline: "CVE-2026-0300 — Palo Alto PAN-OS Captive Portal KEV deadline TODAY (2026-05-09); no patch exists; first patches expected 2026-05-13; CL-STA-1132"
summary: "UPDATE (originally covered 2026-05-07):"
discovered_at: "2026-05-09T05:00:12Z"
event_date: null
run_id: 2026-05-09-migrated
priority: notable
immediate_action: null
tags:
  - vulnerabilities
  - actively-exploited
  - cisa-kev
  - pre-auth
  - rce
  - zero-day
regions:
  - global
sectors:
  - public-sector
  - defense
entities:
  - "campaign:cl-sta-1132"
cves: []
sources:
  - url: "https://security.paloaltonetworks.com/CVE-2026-0300"
    publisher: "Palo Alto Security Advisory — CVE-2026-0300 update, 2026-05-08"
    role: primary
  - url: "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
    publisher: CISA KEV catalog
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: "migration: update target unresolved (originally covered 2026-05-07)"
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-05-09.md
---

**UPDATE (originally covered 2026-05-07):**

The CISA KEV deadline for CVE-2026-0300 (Palo Alto PAN-OS Captive Portal unauthenticated root RCE, CVSS 9.3) is **today, 2026-05-09**. Palo Alto Networks has **not yet released a firmware patch**; the vendor statement from 2026-05-08 confirmed the earliest expected maintenance release containing a code fix is **PAN-OS 10.1.14 / 10.2.12 / 11.0.5 / 11.1.4**, expected 2026-05-13. Organisations in US federal scope that cannot meet the KEV deadline through mitigating action face a compliance gap until that release.

Palo Alto's mitigation guidance remains: disable Captive Portal (`Device > User Identification > Captive Portal Settings > uncheck Enable Captive Portal`) or disable GlobalProtect and Captive Portal if not operationally needed. Threat Prevention signatures 95817/95818/95820 block the known exploitation chain. PA-Series hardware appliances running content update < 8765-9032 are not covered by the signatures.

Post-exploitation detail added: Palo Alto Unit 42 published a threat bulletin on 2026-05-08 confirming **CL-STA-1132** (a China-nexus cluster it tracks separately from previous PAN-OS attackers) as the primary exploitation actor. Unit 42 observed this cluster: creating rogue admin accounts via the GlobalProtect daemon (bypassing normal `admin-role` RBAC), exporting full running configurations including pre-shared keys, installing Python-based tunnelling implants under `/tmp/.update-service`, and performing internal reconnaissance via OSPF route table queries. The cluster's dwell time before detection was 4–17 days across confirmed victims. The rogue admin account naming pattern (`svc-health-check-[6-digit-numeric]`) has been observed consistently and can be used as a hunting indicator.
