Palo Alto Networks has issued a warning to customers about a critical, unpatched remote code execution (RCE) vulnerability in PAN-OS software that is being exploited in active attacks. Multiple outlets report that the issue affects the User-ID Authentication Portal, which is also described as the Captive Portal service. The portal is used for user identification for network traffic when the firewall cannot automatically map an IP address.
The vulnerability is identified as CVE-2026-0300. Security reports describe it as a buffer overflow flaw that can lead to root-level code execution. Palo Alto Networks says the vulnerability is already under exploitation, but a permanent fix is still in development, according to the outlets’ reporting. Customers are urged to apply available mitigations or mitigations recommended by Palo Alto Networks to reduce exposure while patches are being finalized.
Overall, the reports agree on the same core details: the affected component is the User-ID Authentication Portal in PAN-OS, the flaw is CVE-2026-0300, it is being exploited in the wild, and the company is coordinating guidance and mitigations ahead of a finalized fix.