Nation-state actors exploit Palo Alto PAN-OS zero-day for weeks

2026-05-08T02:51:42Zd40dca9067df2fff588a133b3127d234773580fee641e5fe5565100cd89122a5
adbapachebotnetchaos ransomwarecisaciscocode executionddosdouble-freehttp2iotivantiivanti-epmmknown exploited vulnerabilitiesmiraimuddywaternation-statepalo altopan-osrcesecurity-patchssrfvulnerabilityxlabs_v1zero-day

What happened

Multiple high‑impact security incidents and patches: Palo Alto PAN‑OS zero‑day CVE‑2026‑0300 (buffer overflow, CVSS 9.3) is being actively exploited — including by suspected nation‑state actors — for unauthenticated RCE, root access and persistence (tunneling tools like EarthWorm/ReverseSocks5 used); CISA added CVE‑2026‑0300 to its Known Exploited Vulnerabilities catalog. CISA also added Ivanti Endpoint Manager Mobile CVE‑2026‑6973 (CVSS 7.1) to KEV. Apache HTTP Server fixes include CVE‑2026‑23918 (HTTP/2 double‑free, RCE, CVSS 8.8). Cisco released patches for high‑severity flaws (including CV

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
d40dca9067df2fff588a133b3127d234773580fee641e5fe5565100cd89122a5
Enrichment time
2026-05-08T02:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.