
PAN-OS
Palo Alto Networks firewall and SD-WAN OS; repeatedly targeted by state actors exploiting perimeter-device flaws.
PAN-OS is Palo Alto Networks' firewall operating system, targeted since 16 April 2026 by state-sponsored cluster CL-STA-1132 through a captive-portal authentication bypass patched only after a CISA federal deadline had already passed.
Last refreshed: 3 August 2026 · Appears in 1 active topic
Why are firewalls becoming the preferred entry point for ransomware gangs?
Timeline for PAN-OS
Mentioned in: KEV patch clocks fell to three days
Cybersecurity: Threats and DefencesMentioned in: Splunk lands its first-ever KEV entry
Cybersecurity: Threats and DefencesMentioned in: CISA tears up its KEV deadline rules
Cybersecurity: Threats and DefencesMentioned in: Arista refuses to patch KEV flaw
Cybersecurity: Threats and DefencesVPN zero-day open a month pre-patch
Cybersecurity: Threats and DefencesBackground
PAN-OS is the operating system running Palo Alto Networks' next-generation firewalls, SD-WAN appliances and Panorama management infrastructure. In May 2026 it became the first product in CISA's history to receive a federal KEV remediation Deadline that preceded the vendor's own patch: CVE-2026-0300, an unauthenticated Remote Code Execution flaw in the captive portal component (CVSS 9.3), was listed on 6 May with a 9 May federal Deadline, four days before Palo Alto shipped the fix on 13 May. state-sponsored cluster CL-STA-1132 had been exploiting the flaw since 16 April, with tradecraft including nginx shellcode injection, Active Directory enumeration via the firewall's service account, and systematic log destruction .
PAN-OS sits at the network perimeter in enterprise and government environments globally, making it a structurally attractive target: a root-level compromise converts a security control into a trusted pivot point. The CVE-2026-0300 campaign is one instance of a broader 2026 pattern in which edge devices, VPN gateways, firewalls, SD-WAN concentrators, are the preferred ransomware and state-actor entry vector, alongside a Check Point VPN zero-day confirmed the same reporting cycle .
Palo Alto's own Unit 42 team confirmed the exploitation before a patch existed, an accountability precedent CISA subsequently applied to the Exchange Server OWA zero-day the following week, suggesting the pre-patch Deadline is now settled policy rather than a one-off.