Today: 13 May 2026
Palo Alto Networks Zero-Day Alert Puts PAN-OS Firewall Customers on Patch Watch
8 May 2026
2 mins read

Palo Alto Networks Zero-Day Alert Puts PAN-OS Firewall Customers on Patch Watch

SANTA CLARA, California, May 7, 2026, 15:02 PDT

  • Palo Alto Networks reported that threat actors have taken advantage of the critical PAN-OS firewall vulnerability, CVE-2026-0300.
  • Customers will have to rely on mitigations for the time being, with fixes scheduled to roll out in phases starting May 13.
  • Palo Alto shares climbed along with the rest of the cybersecurity group, even as the warning landed during a wider sector rally.

Palo Alto Networks flagged a critical vulnerability in its PAN-OS firewall software and told customers attackers have already exploited it. The company’s initial software patches aren’t set to arrive until May 13.

CVE-2026-0300, the bug in question, hits the User-ID Authentication Portal—or Captive Portal—on both PA-Series and VM-Series firewalls. Palo Alto Networks slapped it with a critical rating and a 9.3 severity score. The issue? Attackers without credentials could potentially execute code as root, handing them total control of any affected device, if they send specially crafted network packets.

The issue hits right at the network edge—these products sit between internal systems and the internet, where firewalls do the heavy lifting. With a zero-day like this, no complete patch is ready, so customers are stuck using workarounds for at least several days.

Palo Alto’s Unit 42 research team is calling the activity CL-STA-1132, describing it as a probable state-sponsored cluster. So far, they’ve only observed limited exploitation, according to their report. Attackers exploited the bug for remote code execution—RCE—executing commands remotely before planting shellcode in an nginx worker process and wiping logs along with other traces, the researchers said.

Rapid7 flagged that the vulnerability hits PA-Series and VM-Series appliances if the Authentication Portal is turned on; Prisma Access, Cloud NGFW, and Panorama don’t fall under that risk. Shodan, according to the security firm, turned up roughly 225,000 internet-facing PAN-OS instances—a number that signals broad exposure, though it doesn’t mean every system is at risk.

The U.S. Cybersecurity and Infrastructure Security Agency put the flaw on its Known Exploited Vulnerabilities list on May 6, according to Cybersecurity Dive. Palo Alto notified customers that initial patches are slated for May 13, with further updates coming May 28.

Palo Alto Networks is advising customers to limit Authentication Portal access to trusted internal zones for the time being, or to disable response pages on interfaces exposed to the internet. If the portal isn’t needed, just turn it off. The company also mentioned that users with a Threat Prevention subscription have the option to enable Threat ID 510019.

Security experts warn the patch gap is raising risk levels. “Treat every internet-exposed PA-Series and VM-Series firewall as a compromise candidate until forensics prove otherwise,” Collin Hogue-Spears, senior director of solution management at Black Duck, told SC Media. Polygraf AI chief executive Yagub Rahimov described the activity as “a clear targeted operation.” SC Media

The real danger doesn’t stop at the first intrusion. According to Unit 42, after getting inside, attackers relied on open-source tunneling software like EarthWorm and ReverseSocks5. From there, they pivoted toward Active Directory—the Microsoft platform central to user and access controls in most organizations. That escalation can shift a simple firewall compromise into a much larger identity security mess.

But it all comes down to how many customers left the portal open to untrusted networks—and how quickly those mitigations get implemented. If attackers ramp up scanning activity before patches land, Palo Alto may be staring at a bigger cleanup and a tougher round of reputational questions, even with the company’s advisory pointing out that customers sticking to standard practice face less risk.

Palo Alto Networks saw its stock jump roughly 7% Thursday, changing hands close to $196.53. Cybersecurity stocks broadly moved higher, buoyed by Fortinet’s strong earnings and renewed investor appetite for AI-driven security software. According to MarketWatch, CrowdStrike and Zscaler posted gains as well, with Fortinet’s results lifting sentiment across the sector.

On one hand, a firewall exploit was running live. On the other, sector trades stayed lively. For Palo Alto Networks, the immediate concern isn’t so much what the stock does, but whether clients can actually seal the open portals ahead of the patch cycle.

Stock Market Today

  • Soybeans Rally as USDA Cuts U.S. Stock Estimates and Boosts Crush Data
    May 13, 2026, 12:55 PM EDT. Soybean futures surged Tuesday, with contracts gaining between 10 1/4 and 13 3/4 cents. The USDA's WASDE report cut the U.S. old crop soybean carryout by 10 million bushels (mbu) to 340 mbu, driven by a 10 mbu export reduction and a 20 mbu increase in soybean crush. New crop ending stocks were revised sharply lower to 310 mbu from 366 mbu estimate. The U.S. production outlook was set at 4.435 billion bushels, with a yield forecast of 53 bushels per acre. South American production remained unchanged. U.S. planting progress stood at 49%, well ahead of the 36% average. Soymeal and soy oil futures also advanced, reflecting market tightening and strong fundamentals.

Latest articles

UiPath Stock Drops as Its AI Agent Bet Hits a Hard Earnings Test

UiPath Stock Drops as Its AI Agent Bet Hits a Hard Earnings Test

13 May 2026
UiPath Inc. shares dropped 5.9% to $9.42 on Wednesday, with trading volume above 22 million, after the company launched a new integration for AI coding agents but investors waited for clearer demand signals ahead of its May 28 earnings call. UiPath reported fourth-quarter revenue of $481 million, up 14%, and reached full-year GAAP profitability for the first time.
Wolfspeed Stock Jumps 21% as Citrini Research Reprices AI Power-Chip Bet

Wolfspeed Stock Jumps 21% as Citrini Research Reprices AI Power-Chip Bet

13 May 2026
Wolfspeed shares surged over 21% to $65.13 Wednesday, with trading volume exceeding 18 million shares and market value reaching $2.55 billion. The rally followed Citrini Research’s endorsement, tying Wolfspeed’s silicon carbide chips to rising AI data-center demand. Wolfspeed reported a $120 million net loss last quarter and expects negative gross margins to continue. Some analysts remain cautious despite the stock’s recent gains.
LinkedIn Layoffs 2026: Why Microsoft’s Job Cuts Hit Even as Revenue Grows

LinkedIn Layoffs 2026: Why Microsoft’s Job Cuts Hit Even as Revenue Grows

13 May 2026
LinkedIn will cut about 5% of its workforce, affecting roles in marketing, engineering, and product teams, according to internal memos and sources. The move comes as LinkedIn reported a 12% revenue increase last quarter and surpassed 1.3 billion members. The company has over 17,500 employees worldwide. Microsoft shares were little changed following the news.

Popular

Berkshire Hathaway Stock Rises Today as Inflation Makes Its Cash Hoard Matter Again

Berkshire Hathaway Stock Rises Today as Inflation Makes Its Cash Hoard Matter Again

12 May 2026
Berkshire Hathaway’s Class B shares climbed 1.4% to $486.46 Tuesday after April CPI data showed inflation up 0.6% for the month and 3.8% year-over-year. The company reported $11.35 billion in first-quarter operating earnings, up from $9.64 billion a year earlier. Berkshire held $373.5 billion in cash and short-term Treasuries at March 31. Prediction markets showed a 97.5% chance of no Fed rate change in June.
Cloudflare AI Layoffs: 1,100 Jobs Cut as Shares Fall After Forecast Miss
Previous Story

Cloudflare AI Layoffs: 1,100 Jobs Cut as Shares Fall After Forecast Miss

SiTime Stock Jumps 28% as AI Data-Center Demand Almost Doubles Sales
Next Story

SiTime Stock Jumps 28% as AI Data-Center Demand Almost Doubles Sales

Go toTop