Skip to content
You can now search across every topic, entity and event.What's new
PAN-OS
TechnologyUS

PAN-OS

Palo Alto Networks firewall and SD-WAN OS; repeatedly targeted by state actors exploiting perimeter-device flaws.

PAN-OS is Palo Alto Networks' firewall operating system, targeted since 16 April 2026 by state-sponsored cluster CL-STA-1132 through a captive-portal authentication bypass patched only after a CISA federal deadline had already passed.

Last refreshed: 3 August 2026 · Appears in 1 active topic

Key Question

Why are firewalls becoming the preferred entry point for ransomware gangs?

Timeline for PAN-OS

#12 28 Jul

Mentioned in: KEV patch clocks fell to three days

Cybersecurity: Threats and Defences
#8 18 Jun

Mentioned in: Splunk lands its first-ever KEV entry

Cybersecurity: Threats and Defences
#8 10 Jun

Mentioned in: CISA tears up its KEV deadline rules

Cybersecurity: Threats and Defences
#7 9 Jun

Mentioned in: Arista refuses to patch KEV flaw

Cybersecurity: Threats and Defences
#7 8 Jun

VPN zero-day open a month pre-patch

Cybersecurity: Threats and Defences
View full timeline →

Background

PAN-OS is the operating system running Palo Alto Networks' next-generation firewalls, SD-WAN appliances and Panorama management infrastructure. In May 2026 it became the first product in CISA's history to receive a federal KEV remediation Deadline that preceded the vendor's own patch: CVE-2026-0300, an unauthenticated Remote Code Execution flaw in the captive portal component (CVSS 9.3), was listed on 6 May with a 9 May federal Deadline, four days before Palo Alto shipped the fix on 13 May. state-sponsored cluster CL-STA-1132 had been exploiting the flaw since 16 April, with tradecraft including nginx shellcode injection, Active Directory enumeration via the firewall's service account, and systematic log destruction .

PAN-OS sits at the network perimeter in enterprise and government environments globally, making it a structurally attractive target: a root-level compromise converts a security control into a trusted pivot point. The CVE-2026-0300 campaign is one instance of a broader 2026 pattern in which edge devices, VPN gateways, firewalls, SD-WAN concentrators, are the preferred ransomware and state-actor entry vector, alongside a Check Point VPN zero-day confirmed the same reporting cycle .

Palo Alto's own Unit 42 team confirmed the exploitation before a patch existed, an accountability precedent CISA subsequently applied to the Exchange Server OWA zero-day the following week, suggesting the pre-patch Deadline is now settled policy rather than a one-off.

Common Questions
Why are firewalls being targeted instead of endpoints in 2026 ransomware attacks?
Edge devices such as PAN-OS firewalls and VPN gateways process untrusted traffic before endpoint controls, sit outside host-based detection, and carry privileged network credentials. A perimeter compromise gives attackers a trusted pivot point inside the network without needing to touch a single endpoint.Source: event
What is CL-STA-1132 and which countries does it target?
CL-STA-1132 is a state-sponsored threat cluster attributed by Palo Alto's Unit 42 research team. It conducted the known exploitation of PAN-OS CVE-2026-0300 from 16 April 2026. Specific country attribution has not been publicly confirmed.Source: Palo Alto Unit 42
What did attackers do after exploiting the PAN-OS captive portal flaw?
CL-STA-1132 injected shellcode into nginx worker processes, enumerated Active Directory via the firewall's service account, moved laterally using EarthWorm and ReverseSocks5, and methodically destroyed crash logs and kernel messages to cover their tracks.Source: Palo Alto Unit 42
How did CL-STA-1132 exploit PAN-OS?
CL-STA-1132 exploited CVE-2026-0300 to inject shellcode into PAN-OS nginx worker processes, then used the firewall's own Active Directory service account to enumerate the network, moved laterally with EarthWorm and ReverseSocks5, and destroyed logs.Source: Unit 42
Why did CISA set a PAN-OS patch deadline before Palo Alto had a fix ready?
CISA listed CVE-2026-0300 on 6 May 2026 with a 9 May federal Deadline, four days before Palo Alto shipped the patch on 13 May. It was the first time a federal KEV Deadline preceded the vendor's own fix. CISA acted because active state-actor exploitation had already been running for six weeks.Source: CISA KEV / Palo Alto advisory
Is my Palo Alto firewall vulnerable to CVE-2026-0300?
PAN-OS versions with captive portal enabled are affected by CVE-2026-0300 (CVSS 9.3). CISA's federal Deadline was 9 May 2026; Palo Alto Networks' own patch was scheduled for 13 May. Organisations should check Palo Alto's security advisory for affected versions and apply mitigations immediately.Source: CISA / Palo Alto Networks
Source Material