CVE-2026-0300
View CSAF Summary A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to exec...
Affects 50 products across 3 vendors.
Software writes data past buffer boundaries, corrupting memory and potentially enabling code execution.
A critical buffer overflow vulnerability exists in the User-ID™ Authentication Portal service of Palo Alto Networks PAN-OS software, affecting Siemens RUGGEDCOM APE1808 devices. This vulnerability allows an unauthenticated attacker to execute arbitrary code with root privileges, posing significant risks to the operational integrity and security of affected systems.
BSID: BS-2026-GLOBAL-271192-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-0300?
What is the CVSS score for CVE-2026-0300?
Is CVE-2026-0300 actively exploited?
How do I remediate CVE-2026-0300?
What systems are affected by CVE-2026-0300?
What NERC-CIP standard applies to CVE-2026-0300?
What IEC 62443 requirement maps to CVE-2026-0300?
| CVE ID | CVE-2026-0300 |
|---|---|
| BSID | BS-2026-GLOBAL-271192-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Published | 2026-05-19 |
| Last Modified | 2026-05-19 |
| ICS Relevance | 100% |
| Weakness (CWE) | |
| Verticals | |
| Domains | |
| Source | NVD |
View CSAF Summary A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. Siemens is preparing fix versions and recommends countermeasures for products where fixes are not, or not yet available. Customers are advised to consult and implement the workarounds
Source: NIST NVD / MITRE CVE Database
The vulnerability can be exploited remotely without authentication. An attacker can send specially crafted packets to the User-ID™ Authentication Portal service, leading to a buffer overflow and potential execution of arbitrary code with root privileges.
Exploitation Likelihood: CRITICAL
| CISA KEV | ● Active Exploitation Confirmed (added 2026-05-06) |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Implement network segmentation and access controls to limit exposure to the vulnerable service. Monitor network traffic for suspicious activity and apply recommended workarounds from the vendor.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.
This vulnerability violates CIP-007-R2 as it allows unauthorized access to critical control system functions, which could compromise the reliability and security of the power grid.
This vulnerability maps to SR 7.6 because it involves a buffer overflow that can lead to unauthorized control of the device, which is a critical security concern in ICS environments.
Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.
SAGE Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 1fcfd7e4b6c7b5bfe8ebefafdf5e4277d33adf5ace346f471d4eef18e9373a4a1aad894dadcc6e990b11c7795c1aa279f1a58e83d11b8ceebe4921aa95e3221a |
This Vulnerability Is Being Actively Exploited
CVE-2026-0300 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider alerts your team within 15 minutes when KEV vulnerabilities match your ICS assets.
Start Free KEV Monitoring →