INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Exploitation of PAN-OS Captive Portal Zero-Day

| 2026-05-07 00:00 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The threat landscape is evolving, with nation-state actors increasingly focusing on edge-network technological assets. Palo Alto Networks' Cortex Xpanse can identify exposed instances of the User-ID Authentication Portal potentially vulnerable to CVE-2026-0300, a buffer overflow vulnerability that allows an unauthenticated attacker to execute arbitrary code with root privileges. This vulnerability was identified by the company in response to a threat brief from Unit 42, which reported limited exploitation of the same vulnerability at this time.
Technical Mitigations AI-generated
• Restrict User-ID Authentication Portal access exclusively to trusted internal IP addresses and ensure the portal is not publicly reachable. • Implement a firewall configuration that restricts network traffic to only necessary ports and protocols for PAN-OS software services. • Use Palo Alto Networks Cortex Xpanse or Unit 42 Incident Response team engagement to identify exposed instances of the User-ID Authentication Portal.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

e11f69••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
Re•••••.tar
138.0.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
APT41APT41Volt TyphoonVolt Typhoon CVE-2026-0300CVE-2026-0300
Target & Sectors
NORTH_AMERICA NORTH_AMERICA MIDDLE_EAST MIDDLE_EAST EUROPE EUROPE governmentgovernment
Incident Timeline
‎April 9, 2026
Threat actors exploited a zero-day vulnerability in the General Document Context of PAN-OS devices starting April 9, 2026.
‎April 29, 2026
Nation-state actors exploited a zero-day vulnerability in Palo Alto PAN-OS to gain unauthorized access and commandeer the targeted device.
‎May 6, 2026
Palo Alto Networks released a security advisory on May 6, 2026, identifying CVE-2026-0300 as the buffer overflow vulnerability in its User-ID Authentication Portal service.
vulnerability CVE-2026-0300
tactic Buffer Overflow
organisation Palo Alto Networks
organisation User-ID
‎2026/05/07
Nation-state threat actors exploited a buffer overflow vulnerability in the User-ID Authentication Portal service of Palo Alto Networks PAN-OS software to gain unauthorized access and execute arbitrary code with root privileges on PA-Series and VM-Series firewalls.
organisation IoT
organisation PAN
organisation Palo Alto Networks
organisation User-ID
organisation Shadowserver
organisation Palo Alto Networks Cortex Xpanse
organisation the User-ID Authentication Portal
organisation Current Scope of the Attack Using CVE-2026-0300
organisation Cortex Xpanse
organisation PAN-OS
infrastructure Windows
infrastructure Linux
infrastructure Macos
infrastructure 67.206.213
infrastructure 136.0.8
infrastructure 146.70.100
infrastructure 149.104.66
infrastructure 2.0
infrastructure 2.0-linux
infrastructure 532.31
infrastructure 5.5
infrastructure 10.0
infrastructure 537.36
organisation hxxps[:]//github[.]com/Acebond
organisation Mozilla/5.5 (Windows NT 10.0
organisation Win64
organisation KHTML
organisation SecurityAffairs
organisation Bridges
organisation Encapsulates
organisation RDP
organisation SSH
infrastructure 11.1
infrastructure 82.080.467
infrastructure 138.0.0
organisation Attacker User
organisation /tmp/.c
organisation Prisma Access
organisation Panorama
organisation Prisma Access None
organisation User-ID Authentication Portal
organisation IP
organisation User-ID Authentication Portal (Captive Portal
organisation RCE
organisation EarthWorm
threat_actor Volt Typhoon
threat_actor APT41
organisation NAT
organisation Restrict User-ID Authentication Portal
organisation Response Pages
organisation the Interface Management Profile
organisation Keep Response Pages
organisation Live Community
organisation Disable User-ID Authentication Portal
organisation Threat ID 510019
organisation Applications
organisation CL-STA-1132
organisation Cyber Threat Alliance
organisation CTA
organisation Cloud-Delivered Security Services
organisation DNS Security
infrastructure 12.1
infrastructure 12.1.4-h5
infrastructure 12.1.7
organisation ETA
‎May 8, 2026
Threat actors used a General Document Context (Unidentified Python Script) to target Palo Alto PAN-OS.
tactic T1059.006 - Python
‎May 9, 2026
Palo Alto PAN-OS, a network security system, was exploited by nation-state actors through a zero-day vulnerability.
‎May 13, 2026
Threat actors exploited a zero-day vulnerability in Palo Alto PAN-OS, targeting nation-state actors.
‎May 13
CyberScoop reported that a Palo Alto PAN-OS zero-day exploit was being targeted by nation-state actors.
organisation CyberScoop
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎Macos
Affected Product
Metrics
infrastructure
‎11.1
Software Version
Metrics
infrastructure
‎82.080.467
Software Version
Metrics
infrastructure
‎67.206.213
Software Version
Metrics
infrastructure
‎136.0.8
Software Version
Metrics
infrastructure
‎146.70.100
Software Version
Metrics
infrastructure
‎149.104.66
Software Version
Metrics
infrastructure
‎2.0
Software Version
Metrics
infrastructure
‎2.0-linux
Software Version
Metrics
infrastructure
‎532.31
Software Version
Metrics
infrastructure
‎5.5
Software Version
Metrics
infrastructure
‎10.0
Software Version
Metrics
infrastructure
‎537.36
Software Version
Metrics
infrastructure
‎138.0.0
Software Version
Metrics
infrastructure
‎12.1
Software Version
Metrics
infrastructure
‎12.1.4-h5
Software Version
Metrics
infrastructure
‎12.1.7
Software Version