🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.

Palo Alto Networks PAN-OS Captive Portal RCE (CVE-2026-0300) | MSSP Advisory

Critical🔴 KEV ALERT
DateMay 6, 2026
CVECVE-2026-0300
📋Executive Summary
CISA flagged CVE-2026-0300, a root-level code execution vulnerability in Palo Alto PAN-OS captive portal services that allows unauthenticated remote attacks. This hits both your network perimeter infrastructure and every client running Palo Alto firewalls.
⚠️Why It Matters for MSSPs
Your own Palo Alto devices protecting your RMM and PSA environments are exposed to immediate root compromise from unauthenticated attackers. Every client with Palo Alto firewalls expects you to know about this vulnerability and guide their response before they read about it elsewhere.
Recommended Action
Audit all Palo Alto devices in your environment and client environments within 24 hours. Implement the workarounds immediately by restricting captive portal access to trusted zones only or disabling it entirely if unused.
🔒
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
Get your first advisory free →
🏷️Threat Category
Zero-Day

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.