PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-0300 Palo Alto Networks CVE debrief

CVE-2026-0300 is an out-of-bounds write vulnerability in Palo Alto Networks PAN-OS that CISA added to the Known Exploited Vulnerabilities catalog on 2026-05-06. The supplied CISA entry includes urgent mitigation guidance: apply vendor mitigations when available, restrict User-ID Authentication Portal access to trusted zones, and disable the portal if it is not required.

Vendor
Palo Alto Networks
Product
PAN-OS
CVSS
CRITICAL 10
CISA KEV
Listed
Original CVE published
2026-05-06
Original CVE updated
2026-05-06
Advisory published
2026-05-06
Advisory updated
2026-05-06

Who should care

Security teams, network administrators, and asset owners responsible for Palo Alto Networks PAN-OS deployments should treat this as a high-priority item, especially where the User-ID Authentication Portal is exposed or in use.

Technical summary

The available source data identifies the issue as an out-of-bounds write in PAN-OS. CISA’s KEV listing means the vulnerability has met CISA’s known-exploitation criteria and should be handled as an urgent defensive response item. The source corpus does not provide affected versions, exploit details, or vendor fix status beyond the workaround guidance included in the KEV record.

Defensive priority

High

Recommended defensive actions

  • Apply Palo Alto Networks’ official mitigations or fix as soon as they are available.
  • Restrict User-ID Authentication Portal access to only trusted zones.
  • Disable the User-ID Authentication Portal if it is not required.
  • Validate whether any PAN-OS systems are in scope and exposed to the portal.
  • If mitigations are unavailable, follow applicable BOD 22-01 guidance for cloud services or discontinue use of the product as directed by CISA.

Evidence notes

This debrief is limited to the supplied source corpus: the CVE metadata, the CISA KEV JSON entry, and official record links (CVE.org and NVD). The corpus provides the vulnerability class, CISA KEV status, date added, due date, and specific workaround guidance, but it does not include a vendor advisory excerpt, affected version ranges, or CVSS details.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-0300 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-0300

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-0300 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-0300

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.