Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution

2026-05-07T20:51:57Z6180d64ccb2e36ddb0c24a20ad30cc7f5a09aadf4a51d05efe44e52b7add8952
TGR-STA-1030agentcoreai-browser-extensionsair-snitchawsbedrockbuffer-overflowcaptive-portaldata-exfiltrationiotkuberneteslinux-kernellocal-privilege-escalationmirainpmpan-osremote-code-executionsupply-chainthreat-actorwifi-bypasszero-day

What happened

Unit 42 released multiple research briefs including an active exploitation of a PAN‑OS captive portal zero‑day (CVE-2026-0300) — a buffer overflow enabling unauthenticated remote code execution — and a separate critical Linux kernel local privilege escalation dubbed “Copy Fail” (CVE-2026-31431). Additional coverage highlights escalating npm supply‑chain threats, high‑risk AI browser extensions that steal data, AirSnitch Wi‑Fi bypasses, AWS Bedrock/AgentCore sandbox and IAM weaknesses, Kubernetes attack trends, and attempted exploitation of TP‑Link router vulnerability CVE-2023-33538.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
paloalto_unit42
Record identifier
6180d64ccb2e36ddb0c24a20ad30cc7f5a09aadf4a51d05efe44e52b7add8952
Enrichment time
2026-05-07T20:51:57Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.