Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution

2026-05-08T20:51:40Z67380335c6a6d8d989b7bef60d77272c6d95056f4e10fba47f12d737773ddf5d
CVE-2026-0300CVE-2026-31431PAN-OSai-browser-extensionsbuffer overflowcaptive portalexploitationkuberneteslinux-kernellocal privilege escalationnpmpatchingsupply-chainunauthenticated remote code executionunit42vulnerabilityzero-day

What happened

Unit 42 reports an actively exploited PAN‑OS User‑ID Authentication Portal buffer‑overflow zero‑day (CVE-2026-0300) that enables unauthenticated remote code execution against affected PAN‑OS devices; immediate patching and mitigations are recommended. The feed also highlights Copy Fail (CVE-2026-31431), a critical Linux kernel local‑privilege‑escalation impacting millions, and additional high‑risk themes including npm supply‑chain threats, malicious AI browser extensions, Kubernetes/cloud risk, and ongoing regional actor activity.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
paloalto_unit42
Record identifier
67380335c6a6d8d989b7bef60d77272c6d95056f4e10fba47f12d737773ddf5d
Enrichment time
2026-05-08T20:51:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.