Unit 42 Reports Exploitation of PAN-OS Captive Portal Zero-Day Vulnerability
Palo Alto Networks' Unit 42 has identified active exploitation of CVE-2026-0300, a critical buffer overflow vulnerability in the PAN-OS User-ID Authentication Portal. This zero-day flaw allows unauthenticated attackers to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls by sending specially crafted packets. Although exploitation remains limited, Unit 42 is tracking a state-sponsored threat cluster, CL-STA-1132, responsible for recent attacks. Successful exploits involve injecting shellcode into nginx worker processes, followed by the deployment of tunneling tools like EarthWorm and ReverseSocks5 to establish covert communication channels. Attackers subsequently perform Active Directory enumeration using compromised credentials and systematically destroy logs to evade detection. The vulnerability specifically affects systems where the Captive Portal is exposed to the public internet or untrusted networks. Palo Alto Networks advises restricting portal access to trusted internal IP addresses to mitigate risk. While Prisma Access and Cloud NGFW remain unaffected, customers are urged to apply available protections and consider engaging incident response teams for proactive assessments. This incident highlights the severe risks associated with exposed authentication services and the sophisticated post-exploitation tactics employed by advanced persistent threats.
Wire timeline
Unit 42 Reports Exploitation of PAN-OS Captive Portal Zero-Day Vulnerability
Palo Alto Networks' Unit 42 has identified active exploitation of CVE-2026-0300, a critical buffer overflow vulnerability in the PAN-OS User-ID Authentication Portal. This zero-day flaw allows unauthenticated attackers to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls by sending specially crafted packets. Although exploitation remains limited, Unit 42 is tracking a state-sponsored threat cluster, CL-STA-1132, responsible for recent attacks. Successful exploits involve injecting shellcode into nginx worker processes, followed by the deployment of tunneling tools like EarthWorm and ReverseSocks5 to establish covert communication channels. Attackers subsequently perform Active Directory enumeration using compromised credentials and systematically destroy logs to evade detection. The vulnerability specifically affects systems where the Captive Portal is exposed to the public internet or untrusted networks. Palo Alto Networks advises restricting portal access to trusted internal IP addresses to mitigate risk. While Prisma Access and Cloud NGFW remain unaffected, customers are urged to apply available protections and consider engaging incident response teams for proactive assessments. This incident highlights the severe risks associated with exposed authentication services and the sophisticated post-exploitation tactics employed by advanced persistent threats.
Unit 42