Security Unlocked

Cl-Sta-1132

Threat Intelligence

Palo Alto Captive Portal Zero-Day Under Active Chinese-Linked Exploitation, First Patches May 13

CVE-2026-0300 (CVSS 9.3) is an unauthenticated, root-level RCE in the PAN-OS User-ID Authentication Portal of PA-Series and VM-Series firewalls, under active exploitation by a likely China-aligned cluster Unit 42 tracks as CL-STA-1132. First hotfixes ship May 13. Anything with the Captive Portal exposed to untrusted networks needs immediate mitigation.