CVE-2026-0300
Palo Alto Networks PAN-OS — Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
Weakness-Klassen (CWE)
CWE-787Base
Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
cwe.mitre.org →
Beschreibung
Palo Alto Networks PAN-OS enthält eine Lese-/Schreibzugriff-außerhalb-der-Grenzen-Schwachstelle im User-ID Authentication Portal (auch Captive Portal genannt) Service, die es einem nicht authentifizierten Angreifer ermöglicht, beliebige Code-Ausführung mit Root-Privilegien auf PA-Series und VM-Series Firewalls durchzuführen, indem speziell präparierte Pakete gesendet werden.
Quelle: CISA_KEV
Betroffene Betriebssysteme
other
palo_alto_networks / pan-os10.2.0
other
palo_alto_networks / pan-os10.2.1
other
palo_alto_networks / pan-os10.2.10
other
palo_alto_networks / pan-os10.2.11
other
palo_alto_networks / pan-os10.2.12
other
palo_alto_networks / pan-os10.2.13
other
palo_alto_networks / pan-os10.2.14
other
palo_alto_networks / pan-os10.2.15
other
palo_alto_networks / pan-os10.2.16
other
palo_alto_networks / pan-os10.2.17
other
palo_alto_networks / pan-os10.2.18
other
palo_alto_networks / pan-os10.2.2
other
palo_alto_networks / pan-os10.2.3
other
palo_alto_networks / pan-os10.2.4
other
palo_alto_networks / pan-os10.2.5
other
palo_alto_networks / pan-os10.2.6
other
palo_alto_networks / pan-os10.2.7
other
palo_alto_networks / pan-os10.2.8
other
palo_alto_networks / pan-os10.2.9
other
palo_alto_networks / pan-os11.1.0
other
palo_alto_networks / pan-os11.1.1
other
palo_alto_networks / pan-os11.1.10
other
palo_alto_networks / pan-os11.1.11
other
palo_alto_networks / pan-os11.1.12
Öffentliche Exploit-Referenzen
Öffentliche Proof-of-Concepts und Detection-Templates für diese Schwachstelle. Die Reife reicht von gemeldeten PoCs über funktionsfähige Detection-Skripte bis hin zu vollständig waffenfähigen Exploit-Modulen. NEOSEC mirrort den Code intern für forensische Analysen; nach außen verlinken wir ausschließlich auf die Original-Quellen.
Quellen & Referenzen
Verknüpfte Empfehlungen
- sans-atrisk2026-05-21 00:00 UTCFwd: @RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 20
- sans-atrisk2026-05-14 00:00 UTCFwd: @RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 19
- sans-newsbites-mail2026-05-08 00:00 UTCCritical PAN-OS RCE Flaw Exploited, Awaiting Patch
- sans-newsbites-mail2026-05-05 00:00 UTCLatvian National Sentenced in Connection with Providing Advice to Multiple Ransomware Groups