Nation-state actors exploit Palo Alto PAN-OS zero-day for weeks
2026-05-08T02:51:42Z•d40dca9067df2fff588a133b3127d234773580fee641e5fe5565100cd89122a5
adbapachebotnetchaos ransomwarecisaciscocode executionddosdouble-freehttp2iotivantiivanti-epmmknown exploited vulnerabilitiesmiraimuddywaternation-statepalo altopan-osrcesecurity-patchssrfvulnerabilityxlabs_v1zero-day
What happened
Multiple high‑impact security incidents and patches: Palo Alto PAN‑OS zero‑day CVE‑2026‑0300 (buffer overflow, CVSS 9.3) is being actively exploited — including by suspected nation‑state actors — for unauthenticated RCE, root access and persistence (tunneling tools like EarthWorm/ReverseSocks5 used); CISA added CVE‑2026‑0300 to its Known Exploited Vulnerabilities catalog. CISA also added Ivanti Endpoint Manager Mobile CVE‑2026‑6973 (CVSS 7.1) to KEV. Apache HTTP Server fixes include CVE‑2026‑23918 (HTTP/2 double‑free, RCE, CVSS 8.8). Cisco released patches for high‑severity flaws (including CV
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- d40dca9067df2fff588a133b3127d234773580fee641e5fe5565100cd89122a5
- Enrichment time
- 2026-05-08T02:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.