Palo Alto PAN-OS Captive Portal — unauthenticated root RCE (CVSS 9.3, ITW, KEV deadline 2026-05-09)
cve · CVE-2026-0300
First covered
2026-05-07
Last covered
2026-05-08
Appearances
2
All cited sources for this topic (4)
- security.paloaltonetworks.comprimaryPalo Alto Networks PSIRT — CVE-2026-0300https://security.paloaltonetworks.com/CVE-2026-0300
- cert.europa.euCERT-EU Advisory 2026-006, 2026-05-06https://cert.europa.eu/publications/security-advisories/2026-006/
- cert.ssi.gouv.frCERT-FR CERTFR-2026-AVI-0537, 2026-05-06https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0537/
- unit42.paloaltonetworks.comUnit 42, 2026-05-06https://unit42.paloaltonetworks.com/captive-portal-zero-day/
Story timeline
- 2026-05-08CTI Daily Brief — 2026-05-08
- 2026-05-07CTI Daily Brief — 2026-05-07