Critical Buffer Overflow in Palo Alto Networks PAN-OS User-ID Authentication Portal (CVE-2026-0300)
2026-05-07T07:23:43Z•9bde8b017416c80b257179ca0d9d6d1c1e408cb314c682da3dd4d917482cd05a
authentication portalauthentication-bypassbuffer overflowcaptive portalchaos-ransomwarecopy-failcpanelcredential-harvestcwe-787dwagentexploited-in-the-wildgame.exelinux-lpemetasploitmfa-bypassmuddywaterpalo altopan-osransomwareremote code executionstate-sponsoredthreat-actor
What happened
This Rapid7 blog bundle highlights multiple high-impact security developments: CVE-2026-0300 — a critical, unauthenticated buffer overflow (CWE-787) in the Palo Alto Networks PAN-OS User-ID Authentication/Captive Portal allowing remote arbitrary code execution as root (CVSSv4 9.3) and confirmed exploited in the wild; CVE-2026-41940 — a critical authentication bypass in cPanel & WHM (CVSS 9.8) enabling unauthenticated administrative access; and CVE-2026-31431 (“Copy Fail”) — a Linux kernel cryptographic API logic flaw with public PoC and a new Metasploit local exploit enabling local privilege/“
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 9bde8b017416c80b257179ca0d9d6d1c1e408cb314c682da3dd4d917482cd05a
- Enrichment time
- 2026-05-07T07:23:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.