---
schema: 1
kind: vulnerability
title: >
  Palo Alto PAN-OS CVE-2026-0300 — first-wave fixed builds now scheduled for 2026-05-13; until
  then interim mitigation remains the only option
headline: >
  Palo Alto PAN-OS CVE-2026-0300 — first-wave fixed builds now scheduled for 2026-05-13; until
  then interim mitigation remains the only option
summary: >
  Palo Alto PAN-OS CVE-2026-0300 — first patch wave now scheduled for 2026-05-13 per the vendor
  advisory. The PSIRT page (last update 2026-05-07) lists first-wave fixed builds with ETA 05/13
  and a second wave around 2026-05-28; until the 05/13 builds ship the interim Threat Prevention
  signature 510019 and captive-portal source-IP restriction remain the only mitigations against
  the unauthenticated root RCE that exploitation clusters have been actively abusing (Palo Alto
  Networks PSIRT — CVE-2026-0300).
discovered_at: "2026-05-12T05:00:04Z"
updated_at: "2026-05-13T05:00:13Z"
event_date: null
run_id: 2026-05-12-cd1ab844
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - actively-exploited
  - rce
  - pre-auth
  - cisa-kev
  - patch-available
regions:
  - global
sectors: []
entities:
  - "campaign:cl-sta-1132"
techniques: []
affected_products: []
cves:
  - id: CVE-2026-0300
    cvss: "9.3"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - cisa-kev
      - patch-available
sources:
  - url: "https://security.paloaltonetworks.com/CVE-2026-0300"
    publisher: Palo Alto Networks PSIRT — CVE-2026-0300
    role: primary
  - url: "https://unit42.paloaltonetworks.com/captive-portal-zero-day/"
    publisher: Unit 42 — Captive Portal Zero-Day threat bulletin
    role: corroborating
closed_sources: []
evidence:
  - quote: "UPDATE (originally covered as the 2026-05-07 deep dive; updates 2026-05-08 → 2026-05-10): Palo Alto Networks' PSIRT page for CVE-2026-0300 (last updated 2026-05-07 at time of run) now lists first-wave fixed builds with an ETA of 2026-05-13 for several mainline branches and a second wave around …"
    publisher: ctipilot v2 brief (migrated)
  - quote: "UPDATE (originally covered 2026-05-12): Palo Alto Networks released the first wave of patched PAN-OS builds on 2026-05-13 for the actively-exploited Captive Portal pre-auth RCE, covering PAN-OS 10.2, 11.1, 11.2 and 12.1 (Palo Alto Networks PSIRT, last updated 2026-05-07; patch table confirmed …"
    publisher: ctipilot v2 brief (migrated)
verification: multi-source
sourcing_note: >
  migration: evidence backfilled from v2 brief body (item predates the Evidence footer field);
  migration: update target unresolved (no originally-covered date in v2 body)
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification: null
watchlist_hit: false
actions:
  - "**PAN-OS CVE-2026-0300: deploy patched builds released 2026-05-13.** Apply PAN-OS 12.1.4-h5 / 12.1.7 / 11.2 / 11.1 / 10.2 hot-fix branches on every PA-Series and VM-Series instance running User-ID Captive Portal. Threat Prevention signature ID 510019 remains the interim block."
updates:
  - at: "2026-05-13T05:00:13Z"
    run_id: 2026-05-13-c148b9a5
    type: update
    summary: >
      UPDATE (originally covered 2026-05-12): Palo Alto Networks released the first wave of patched
      PAN-OS builds on 2026-05-13 for the actively-exploited Captive Portal pre-auth RCE, covering
      PAN-OS 10.2, 11.1, 11.2 and 12.1 (Palo Alto Networks PSIRT, last updated 2026-05-07; patch table
      confirmed 2026-05-13).
    fields:
      - actions
      - cves
      - evidence
      - tags
      - body
    merged_from: 2026-05-13/pan-os-cve-2026-0300-first-wave-patched-builds-released-on-2
migrated_from: briefs/2026-05-12.md
---

**UPDATE (originally covered as the 2026-05-07 deep dive; updates 2026-05-08 → 2026-05-10):** Palo Alto Networks' [PSIRT page for CVE-2026-0300](https://security.paloaltonetworks.com/CVE-2026-0300) (last updated 2026-05-07 at time of run) now lists **first-wave fixed builds with an ETA of 2026-05-13** for several mainline branches and a **second wave around 2026-05-28** for the remaining branches; no patched build is yet shipped against the unauthenticated root RCE in the User-ID Authentication Portal / Captive Portal service. The CL-STA-1132 cluster attribution and the ~2026-04-09 first-observed-exploitation date come from Unit 42's separate [Captive Portal Zero-Day threat bulletin](https://unit42.paloaltonetworks.com/captive-portal-zero-day/), not from the PSIRT advisory itself.

Operationally: until the 05/13 first-wave builds ship, the interim Threat Prevention signature **510019** plus source-IP restriction of the captive-portal interface to trusted internal ranges remain the only defender controls for branches that do not yet have a fixed build. PA-Series and VM-Series operators with User-ID Authentication Portal or Captive Portal exposed should treat tomorrow as a pre-staged deployment window — confirm a tested rollback path, validate the interim signature is enforced (Threat Prevention licence required), and verify the captive-portal listener is reachable only from authorised source ranges. Prisma Access, Cloud NGFW and Panorama are not affected. The CISA KEV deadline (2026-05-09) has already expired for FCEB agencies and per PD-13 does not drive Swiss/EU action framing on its own — the operational driver is the actively-exploited ITW status and the imminent first-wave patch ship date.

## Update — 2026-05-13T05:00:13Z

Palo Alto Networks released the first wave of patched PAN-OS builds on 2026-05-13 for the actively-exploited Captive Portal pre-auth RCE, covering PAN-OS 10.2, 11.1, 11.2 and 12.1 ([Palo Alto Networks PSIRT, last updated 2026-05-07; patch table confirmed 2026-05-13](https://security.paloaltonetworks.com/CVE-2026-0300)). Concretely: PAN-OS 12.1.4-h5 (2026-05-13) plus 12.1.7 (planned 2026-05-28); PAN-OS 11.2 multiple builds staged 2026-05-13–2026-05-28; PAN-OS 11.1 and 10.2 on a similar cadence. Prisma Access, Cloud NGFW and Panorama remain unaffected. Threat Prevention signature ID 510019 remains the interim control for any unpatched instance. The CISA KEV deadline of 2026-05-09 is — per the audience-applicability rule in the daily prompt — irrelevant for CH/EU jurisdiction; the operational driver is the active exploitation by CL-STA-1132 documented previously.
