← 목록으로 돌아가기

보안 뉴스 · 취약점

2026-006: Critical Vulnerability in PAN-OS

출처
CERT-EU
원문 게시일
마지막 본문 수집
2026. 09. 14. 16:40 KST

출처: CERT-EU · © Cybersecurity Service for the Union institutions, bodies, offices and agencies (CERT-EU). · CC BY 4.0
문서 서식과 링크를 FineTS 화면에 맞게 정리했습니다. 이미지·첨부파일은 공식 원문에서 확인하세요.

공식 원문에서 읽기 ↗
기사 원문에 등장한 CVE별 취약점, 설명, 조치사항
취약점설명조치사항
CVE-2026-0300

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.

  1. This issue will be fixed in upcoming releases of PAN-OS as captured in the table above. We strongly recommend that you secure access to your User-ID™ Authentication Portal following the instructions in the workarounds section below.
  2. Customers can mitigate the risk of this issue by taking either of the following actions: * Restrict User-ID™ Authentication Portal access to only trusted zones and in addition, disable Response Pages in the Interface Management Profile attached to every L3 interface in any zone where untrusted/internet traffic can ingress. Keep Response Pages enabled only on interfaces in trust/internal zones where legitimate users' browsers ingress. Refer to Step 6 of the following Live Community article (https://live.paloaltonetworks.com/t5/general-articles/why-it-s-essential-to-secure-your-management-interface/ta-p/1001286) and Knowledgebase article (https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000CqbiCAC) for steps to restrict access. * Disable User-ID™ Authentication Portal if not required. Customers with a Threat Prevention subscription can block attacks for this vulnerability by enabling Threat ID 510019 from Applications and Threats content version 9097-10022. Decoder capabilities necessitate PAN-OS 11.1 or a later version for Threat ID support.

한국어 버튼을 눌러 번역을 요청할 수 있습니다.

On 6 May 2026, Palo Alto published a security advisory addressing a critical vulnerability affecting PAN-OS. This vulnerability allows an unauthenticated attacker to execute arbitrary code with root privileges. Palo Alto observed limited exploitation of this vulnerability. It is strongly recommended

History:

  • 06/05/2026 --- v1.0 -- Initial publication

Summary

On 6 May 2026, Palo Alto published a security advisory addressing a critical vulnerability affecting PAN-OS [1]. This vulnerability allows an unauthenticated attacker to execute arbitrary code with root privileges.

Palo Alto observed limited exploitation of this vulnerability. It is strongly recommended updating affected appliances as soon as patches will be available, and to apply workarounds and mitigation in the meantime.

Technical Details

The vulnerability CVE-2026-0300, with the CVSS score of 9.3, is a buffer overflow in the User-ID Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software. [1]

An unauthenticated attacker could execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. [1]

Affected Products

This issue is applicable only to PA-Series and VM-Series firewalls that are configured to use User-ID Authentication Portal.

The following PAN-OS versions are affected:

  • Versions prior to 12.1.4-h5
  • Versions prior to 12.1.7
  • Versions prior to 11.2.4-h17
  • Versions prior to 11.2.7-h13
  • Versions prior to 11.2.10-h6
  • Versions prior to 11.2.12
  • Versions prior to 11.1.4-h33
  • Versions prior to 11.1.6-h32
  • Versions prior to 11.1.7-h6
  • Versions prior to 11.1.10-h25
  • Versions prior to 11.1.13-h5
  • Versions prior to 11.1.15
  • Versions prior to 10.2.7-h34
  • Versions prior to 10.2.10-h36
  • Versions prior to 10.2.13-h21
  • Versions prior to 10.2.16-h7
  • Versions prior to 10.2.18-h6

Additional information is available in the vendor’s advisory [1].

Recommendations

The patches are not available at the time of writing, but are scheduled to be released in the near future. It is recommended updating affected devices as soon as the patches will be released.

Mitigation

It is possible to mitigate the risk of this flaw by taking either of the following actions [1]:

  • Restrict User-ID Authentication Portal access to only trusted zones.
  • Disable User-ID Authentication Portal if not required.

References

[1] https://security.paloaltonetworks.com/CVE-2026-0300

공식 원문에서 읽기 ↗

← 목록으로 돌아가기