Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution
2026-05-08T20:51:40Z•67380335c6a6d8d989b7bef60d77272c6d95056f4e10fba47f12d737773ddf5d
CVE-2026-0300CVE-2026-31431PAN-OSai-browser-extensionsbuffer overflowcaptive portalexploitationkuberneteslinux-kernellocal privilege escalationnpmpatchingsupply-chainunauthenticated remote code executionunit42vulnerabilityzero-day
What happened
Unit 42 reports an actively exploited PAN‑OS User‑ID Authentication Portal buffer‑overflow zero‑day (CVE-2026-0300) that enables unauthenticated remote code execution against affected PAN‑OS devices; immediate patching and mitigations are recommended. The feed also highlights Copy Fail (CVE-2026-31431), a critical Linux kernel local‑privilege‑escalation impacting millions, and additional high‑risk themes including npm supply‑chain threats, malicious AI browser extensions, Kubernetes/cloud risk, and ongoing regional actor activity.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- 67380335c6a6d8d989b7bef60d77272c6d95056f4e10fba47f12d737773ddf5d
- Enrichment time
- 2026-05-08T20:51:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.