PAN-OS in May 2026: Two Vulnerabilities, One Actively Exploited

Two PAN-OS flaws in May 2026: root RCE via the Captive Portal and a GlobalProtect auth bypass. Who is affected and which hardening matters now.

Within one week in May 2026, Palo Alto Networks disclosed two vulnerabilities in PAN-OS – one of them already being actively exploited. On May 5, CVE-2026-0300 was published: an unauthenticated buffer overflow in the User-ID / Captive Portal component that enables remote code execution with root privileges on the firewall – rated by the vendor with a CVSS v4 score of 9.3. Already at disclosure, Palo Alto Networks reported limited active exploitation; since then, public but so far unverified PoC repositories have also been circulating, and CISA has added the vulnerability to the KEV catalog.

On May 13 followed CVE-2026-0257: an authentication bypass in GlobalProtect via forged authentication-override session cookies, rated by the vendor with a CVSS score of 4.7. The flaw only takes effect when authentication-override cookies are enabled and the cookie-signing certificate is reused – but then it grants access to the VPN without valid credentials. Exploitation has not yet been publicly reported; the moderate CVSS score should not, however, obscure the fact that this configuration combination occurs in practice – check your own configuration proactively.

For scale: about 225,000 PAN-OS instances are reachable from the internet according to Shodan. That is the potential attack surface – but actually exploitable via CVE-2026-0300 are only systems on which the Captive Portal is enabled, which is not the shipped default. This distinction is important: it determines whether you are under time pressure or can patch in an orderly way. Anyone who does not know their own configuration must assume the less favorable case.

Who is affected

Affected are the PAN-OS release branches 10.2, 11.1, 11.2, and 12.1. Palo Alto Networks is publishing the fixed versions on a staggered basis per branch – a fix is not yet available for every branch. For exploitability, the following applies:

  • CVE-2026-0300: only firewalls with the Captive Portal enabled (not the default) – but then without authentication and with root privileges.
  • CVE-2026-0257: only GlobalProtect installations with authentication-override cookies enabled in combination with a reused signing certificate.

What to do now

  • Apply available patches immediately: the fixes are appearing staggered per release branch – apply each available fixed version at once and monitor the advisories continuously. CVE-2026-0300 is being actively exploited; here every day counts. For branches without an available fix, the following configuration measures apply until then.
  • Check the Captive Portal and, if unused, disable it: what is not active is not exploitable via CVE-2026-0300 – the most effective immediate measure alongside the patch.
  • Turn off authentication-override cookies or at least use a dedicated, non-reused signing certificate; if abuse is suspected, replace the certificate and invalidate existing sessions.
  • Minimize exposure: the management interface does not belong on the internet; expose GlobalProtect portals only as far as the remote-access need requires.
  • Check logs: examine GlobalProtect logins for unusual patterns and the firewall itself for signs of compromise – especially where the Captive Portal was active.

How sector7 supports you

As an owner-led system house with Palo Alto Networks certification, we check your firewall configuration for the two preconditions for attack and run the patch rollout in a controlled way across HA pairs and sites. Our 24/7 NOC monitoring keeps an eye on your security infrastructure even after the patch – at flat monthly rates.

Sources

Let's talk about your situation.