Junglewise Threat Intelligence

CVE-2026-0300: Palo Alto Networks PAN-OS buffer overflow in User-ID Authentication Portal

CVE-2026-0300 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2026-05-06

Technologies: Siemens Ruggedcom Ape1808, Palo Alto Networks PAN-OS. Vendors: Paloaltonetworks, Siemens, Palo Alto Networks.

Executive brief

Siemens RUGGEDCOM APE1808 devices are affected by a critical vulnerability in the integrated Palo Alto Networks PAN-OS software. This flaw exists in the User-ID Authentication Portal, a service used to manage user access to network resources. An unauthenticated attacker can exploit this to take full control of the device with root privileges, potentially leading to complete network compromise, data theft, or disruption of industrial operations.

Technical details

The vulnerability is an out-of-bounds write (CWE-787) located in the User-ID Authentication Portal (Captive Portal) service of Palo Alto Networks PAN-OS, which is utilized by Siemens RUGGEDCOM APE1808 devices. The flaw is triggered by sending specially crafted packets to the affected service. Because the service runs with high privileges, a successful exploit allows an unauthenticated network-based attacker to execute arbitrary code with root permissions. Siemens is currently preparing fixes; in the interim, mitigations include disabling Response Pages on untrusted interfaces or restricting access to the Authentication Portal to trusted internal IP addresses.

Affected products

  • Siemens RUGGEDCOM APE1808 Devices All versions

Timeline

  • 2026-05-12: advisory: Initial Siemens ProductCERT advisory (SSA-967325) published
  • 2026-05-19: advisory: CISA republication of the advisory

References

Related threats