Palo Alto Zero-Day Exploited in Campaign Bearing Hallmarks of Chinese State Hacking

https://www.securityweek.com/wp-content/uploads/2024/11/Palo-Alto-Networks-zero-day.jpeg

Palo Alto Networks has shared some information on the exploitation of the recently disclosed zero-day vulnerability affecting some of its firewalls. The cybersecurity firm has not directly attributed the attack to a specific threat actor or country, but the evidence seems to point to China.

In an advisory published on May 6, Palo Alto Networks informed customers about CVE-2026-0300, a vulnerability affecting the User-ID Authentication Portal of PA and VM series firewalls.

The company said the flaw, which allows unauthenticated remote code execution with root privileges, had been exploited as a zero-day.

Patches are expected to be released on May 13 and May 28, and in the meantime the company has shared mitigations and workarounds to prevent exploitation.

Shortly after CVE-2026-0300 was disclosed, Palo Alto Networks published a blog post describing the vulnerability’s exploitation in the wild.

According to the company, a “likely state-sponsored” threat group tracked as...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more