Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution
2026-05-07T08:51:44Z•eff35bde4dccedb9dc6460064134a406fdd35d96640263ca3e71066a3a771518
AWS-AgentCoreAirSnitchKubernetesLinux-kernelPAN-OSbrowser-extensionbuffer-overflowcaptive-portaldata-exfiltrationlocal-privilege-escalationnpmsandbox-escapesupply-chainthreat-actorunauthenticated-RCEzero-day
What happened
Unit 42 reports multiple high-impact findings. Most urgent: an actively exploited PAN-OS captive-portal buffer overflow (CVE-2026-0300) in the User-ID Authentication Portal enables unauthenticated remote code execution. Separately, Copy Fail (CVE-2026-31431) is a critical Linux-kernel local privilege escalation that can provide stealthy root on millions of systems. The feed also highlights widespread supply-chain and attacker techniques — npm wormable/multi-stage attacks, high-risk GenAI browser extensions that exfiltrate data and credentials, AirSnitch Wi‑Fi attacks that bypass WPA2/3, AWS/A
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- eff35bde4dccedb9dc6460064134a406fdd35d96640263ca3e71066a3a771518
- Enrichment time
- 2026-05-07T08:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.