Palo Alto Networks says suspected state-sponsored hackers have exploited a critical-severity zero-day vulnerability in its PAN-OS firewalls for nearly a month. The company warns that threat actors are using the flaw in real-world attacks and that there is currently no patch available.
Multiple outlets report that the vulnerability is identified as CVE-2026-0300 and involves a buffer overflow issue in the User-ID Authentication Portal service within PAN-OS. The flaw can be triggered by unauthenticated attackers who send specially crafted packets to internet-facing User-ID Authentication Portals.
Reportedly, the affected products include Palo Alto Networks PA-Series and VM-Series firewalls running vulnerable PAN-OS versions. Palo Alto Networks has notified customers to take protective steps while remediation is pending, as the exploitation is described as ongoing.
The reporting across sources aligns on the vulnerability type, the affected component and models, the method of exploitation (internet-facing portal access without authentication), and the timeline indicating exploitation has been active for close to a month.