In the last day, security researchers flagged a zero-day flaw in Palo Alto Networks PAN-OS Captive Portal that is being actively exploited. If you manage network security gear, this is worth your attention now.
What happened
According to Unit 42, the Palo Alto Networks threat intelligence team, a zero-day in the PAN-OS Captive Portal feature allowed unauthenticated remote code execution. The issue is associated with CVE-2026-0300. In practical terms, this means an attacker could leverage the flaw to run arbitrary code on affected devices and potentially take control of the firewall itself. Captive Portal is used in some networks to manage guest access, so the impact can extend beyond a single device.
For the official background, you can read Unit 42’s coverage on PAN-OS. Unit 42 threat intelligence.
Why it matters
Why you should care if you run PAN-OS devices:
- A remote code execution on a firewall provides a foothold into internal networks and can facilitate further attacks.
- Exposed Captive Portal features can be a target for external actors, especially in guest-access environments.
- Unpatched devices may be at risk even if they’re not directly exposed to the internet—lateral movement can occur from a compromised chassis.
Practical steps you can take now
- Check your PAN-OS devices for Captive Portal exposure and verify you are running a version that has the fix for CVE-2026-0300. Apply the patch or upgrade as soon as possible.
- Review Palo Alto Networks advisories and test the patch in a staging environment before rolling out widely.
- Limit exposure: disable Captive Portal functionality if it’s not needed, or restrict management access to trusted networks and VPNs.
- Enable robust monitoring: watch firewall logs for unusual login attempts, unexpected process launches, or privilege escalations.
- Rotate credentials for administrators and ensure MFA is enforced where possible on management interfaces.
- Implement network segmentation so a compromised firewall can’t immediately reach critical internal services.
- Have an incident response plan ready: know who to call, how to isolate devices, and how to verify patch success.
Final thought
Zero-days are a reminder that patch cycles matter. If you’re unsure about your exposure, start with your most critical PAN-OS devices and work outward. Keeping firmware current and limiting exposure can buy you valuable time while you plan a broader update.