Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
  • Home
  • Attack Feeds
  • A critical Palo Alto PAN-OS zero-day is being exploited in the wild  – CyberScoop
AttackFeed by Joe Wagner | A critical Palo Alto PAN-OS zero-day is being exploited in the wild  - CyberScoop

A critical Palo Alto PAN-OS zero-day is being exploited in the wild  – CyberScoop

Posted on May 6, 2026 By Matt Kapko No Comments on A critical Palo Alto PAN-OS zero-day is being exploited in the wild  – CyberScoop
Attack Feeds

Attackers are actively exploiting a zero-day vulnerability affecting some Palo Alto Networks’ customers’ firewalls, the security vendor said in an advisory Tuesday.

The critical memory corruption vulnerability — CVE-2026-0300 — affects the authentication portal of PAN-OS, and allows unauthenticated attackers to run  code with root privileges on the vendor’s PA-Series and VM-Series firewalls, the company said.

Palo Alto Networks did not say when or how it became aware of active exploitation, nor when the earliest known exploitation occurred. The Cybersecurity and Infrastructure Security Agency added the defect to its known exploited vulnerabilities catalog Wednesday.

The company hasn’t released a patch for the vulnerability or described the scope and objective of confirmed attacks.

“This vulnerability is specific to a limited number of customers with their User-ID Authentication Portal (Captive Portal) exposed to the public internet or untrusted IP addresses. We have observed limited exploitation of this issue and are working to release software fixes, with the first updates expected to be available on May 13,” a Palo Alto Networks spokesperson told CyberScoop.

The company said firewalls exposed to the buffer-overflow vulnerability, which has a CVSS rating of 9.3, are broadly exposed in real-world deployments, and it described the attack complexity as low.

Shadowserver scans found more than 5,800 publicly exposed VM-Series firewalls running PAN-OS as of Tuesday, yet it’s unknown how many of those instances have restricted authentication access to trusted internal IP addresses or disabled the feature altogether.

“We have provided clear mitigation guidance to our customers to secure their environments immediately. This issue does not impact Cloud NGFW or Panorama appliances. We remain committed to a transparent, security-first approach to protect our global customer base,” Palo Alto Networks’ spokesperson added.

Benjamin Harris, CEO and founder of watchTowr, noted that Palo Alto Networks proactively alerted customers to the zero-day, a step that allowed defenders to take action on potentially exposed instances. 

“In a bad situation, that is the best they can do immediately. However, that also alerts everyone to the existence of a vulnerability,” he told CyberScoop.

Despite the risk, Harris said watchTowr expects attacks linked to the zero-day exploit to be “very limited.” 

Palo Alto Networks and its impacted customers remain the only parties to have observed exploitation in the wild, but researchers warn that will likely change soon. 

“It’s likely rules will also start to fire in third-party organizations and honeypots shortly,” Caitlin Condon, vice president of security research at VulnCheck, told CyberScoop. 

“Management interfaces, login pages, and authentication portals have been common adversary targets for both opportunistic and targeted campaigns in recent years,” she added. “With researcher and community eyes on the vulnerability, it’s likely that we’ll see public exploits and broader exploitation quickly, provided the issue isn’t prohibitively difficult to exploit.”

Palo Alto Networks has yet to attribute the attacks to any known threat group, publish indicators or compromise, nor disclose the type of organizations that have been targeted and impacted. 

Researchers are hunting for malicious activity and advise customers to apply patches upon release.

The post A critical Palo Alto PAN-OS zero-day is being exploited in the wild appeared first on CyberScoop.

  –

Read More  – CyberScoop 

Post navigation

❮ Previous Post: ShinyHunters’ Instructure Canvas LMS and Vimeo Breaches Impact Millions of Users  – Hackread – Cybersecurity News, Data Breaches, AI and More
Next Post: A Vulnerability in Apache HTTP Server Could Allow for Remote Code Execution  – Cyber Security Advisories – MS-ISAC ❯

You may also like

Attack Feeds
Urgent warnings from UK and US cyber agencies after Polish energy grid attack  – GRAHAM CLULEY
February 13, 2026
AttackFeed by Joe Wagner | ‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty  - Krebs on Security
Attack Feeds
‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty  – Krebs on Security
April 21, 2026
AttackFeed by Joe Wagner | Bridging the AI Agent Authority Gap: Continuous Observability as the Decision Engine  - The Hacker News
Attack Feeds
Bridging the AI Agent Authority Gap: Continuous Observability as the Decision Engine  – The Hacker News
April 24, 2026
AttackFeed by Joe Wagner | Teenager alleged to be Scattered Spider hacker arrested in Finland, faces US extradition  - GRAHAM CLULEY
Attack Feeds
Teenager alleged to be Scattered Spider hacker arrested in Finland, faces US extradition  – GRAHAM CLULEY
May 4, 2026

Leave a Reply Cancel reply

You must be logged in to post a comment.

  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.