CVE-2026-0300

● KEV CRITICAL

View CSAF Summary A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to exec...

Affects 50 products across 3 vendors.

BCS10.0
CVSS 3.19.8
CVSS v49.3
EPSS32.1%
Percentile98th
PatchPatched
KEV Added2026-05-06
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-787: Out-of-Bounds Write

Software writes data past buffer boundaries, corrupting memory and potentially enabling code execution.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical buffer overflow vulnerability exists in the User-ID™ Authentication Portal service of Palo Alto Networks PAN-OS software, affecting Siemens RUGGEDCOM APE1808 devices. This vulnerability allows an unauthenticated attacker to execute arbitrary code with root privileges, posing significant risks to the operational integrity and security of affected systems.

BSID: BS-2026-GLOBAL-271192-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-0300?
A critical buffer overflow vulnerability exists in the User-ID™ Authentication Portal service of Palo Alto Networks PAN-OS software, affecting Siemens RUGGEDCOM APE1808 devices. This vulnerability allows an unauthenticated attacker to execute arbitrary code with root privileges, posing significant risks to the operational integrity and security of affected systems.
What is the CVSS score for CVE-2026-0300?
CVE-2026-0300 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 32.1%.
Is CVE-2026-0300 actively exploited?
Yes. CVE-2026-0300 is in the CISA KEV catalog (added 2026-05-06). Active exploitation confirmed. Immediate patching required.
How do I remediate CVE-2026-0300?
Priority: IMMEDIATE. Advisory: https://security.paloaltonetworks.com/CVE-2026-0300 PSIRT: [email protected]
What systems are affected by CVE-2026-0300?
CVE-2026-0300 affects: Palo Alto, Palo Alto Networks, Palo Alto Networks, Palo Alto Networks, Palo Alto Networks, Palo Alto Networks, Palo Alto Networks, Palo Alto Networks.
What NERC-CIP standard applies to CVE-2026-0300?
NERC CIP CIP-007 CIP-007-R2: This vulnerability violates CIP-007-R2 as it allows unauthorized access to critical control system functions, which could compromise the reliability and security of the power grid.
What IEC 62443 requirement maps to CVE-2026-0300?
IEC 62443 SR 7.6: This vulnerability maps to SR 7.6 because it involves a buffer overflow that can lead to unauthorized control of the device, which is a critical security concern in ICS environments.
Vulnerability Details
CVE IDCVE-2026-0300
BSIDBS-2026-GLOBAL-271192-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2026-05-19
Last Modified2026-05-19
ICS Relevance100%
Weakness (CWE)
Verticals
ICS-OT
Domains
NETWORK-INFRA
SourceNVD
Official Description

View CSAF Summary A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. Siemens is preparing fix versions and recommends countermeasures for products where fixes are not, or not yet available. Customers are advised to consult and implement the workarounds

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability can be exploited remotely without authentication. An attacker can send specially crafted packets to the User-ID™ Authentication Portal service, leading to a buffer overflow and potential execution of arbitrary code with root privileges.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Palo Alto —
Palo Alto Networks Vm-700
Palo Alto Networks Vm-50
Palo Alto Networks Vm-500
Palo Alto Networks Pan-Os
Palo Alto Networks Pa-5410
Palo Alto Networks Pa-5420
Palo Alto Networks Pa-5430
Palo Alto Networks Pa-5440
Palo Alto Networks Pa-5445
Palo Alto Networks Pa-1410
Palo Alto Networks Pa-1420
Palo Alto Networks Pa-3410
Palo Alto Networks Pa-3420
Palo Alto Networks Pa-3430
Palo Alto Networks Pa-3440
Palo Alto Networks Pa-410
Palo Alto Networks Pa-410R
Palo Alto Networks Pa-410R-5G
Palo Alto Networks Pa-415
Palo Alto Networks Pa-415-5G
Palo Alto Networks Pa-440
Palo Alto Networks Pa-445
Palo Alto Networks Pa-450
Palo Alto Networks Pa-450R
Palo Alto Networks Pa-450R-5G
Palo Alto Networks Pa-455
Palo Alto Networks Pa-455-5G
Palo Alto Networks Pa-455R-5G
Palo Alto Networks Pa-460
Palo Alto Networks Pa-501
Palo Alto Networks Pa-505
Palo Alto Networks Pa-510
Palo Alto Networks Pa-520
Palo Alto Networks Pa-540
Palo Alto Networks Pa-545-Poe
Palo Alto Networks Pa-5450
Palo Alto Networks Pa-550
Palo Alto Networks Pa-5540
Palo Alto Networks Pa-555-Poe
Palo Alto Networks Pa-5550
Palo Alto Networks Pa-5560
Palo Alto Networks Pa-5570
Palo Alto Networks Pa-5580
Palo Alto Networks Pa-560
Palo Alto Networks Pa-7500
Palo Alto Networks Pa-7500-Dpc-A
Palo Alto Networks Vm-100
Palo Alto Networks Vm-300
Siemens Ruggedcom Ape1808
Siemens Ruggedcom Ape1808 Firmware
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 83 Days
CISA KEV● Active Exploitation Confirmed (added 2026-05-06)
Public ExploitNot confirmed
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement network segmentation and access controls to limit exposure to the vulnerable service. Monitor network traffic for suspicious activity and apply recommended workarounds from the vendor.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R2
This vulnerability violates CIP-007-R2 as it allows unauthorized access to critical control system functions, which could compromise the reliability and security of the power grid.
IEC 62443: SR 7.6
This vulnerability maps to SR 7.6 because it involves a buffer overflow that can lead to unauthorized control of the device, which is a critical security concern in ICS environments.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash1fcfd7e4b6c7b5bfe8ebefafdf5e4277d33adf5ace346f471d4eef18e9373a4a1aad894dadcc6e990b11c7795c1aa279f1a58e83d11b8ceebe4921aa95e3221a
Related CVEs affecting Palo Alto
CVE-2026-0263 9.8 A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks... CVE-2026-0257 9.1 Authentication bypass vulnerabilities in the GlobalProtect portal and gateway... CVE-2026-0259 8.8 An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFir... CVE-2026-0240 8.7 An information disclosure vulnerability in Trust Protection Foundation enable... CVE-2026-0244 8.1 An improper certificate validation vulnerability in the Palo Alto Networks Pr...
View all Palo Alto CVEs →

This Vulnerability Is Being Actively Exploited

CVE-2026-0300 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider alerts your team within 15 minutes when KEV vulnerabilities match your ICS assets.

Start Free KEV Monitoring →