CVE-2026-0300 – Palo Alto Cloud NGFW
“When your firewall is vulnerable, your entire network is exposed.”
This patch addresses CVE-2026-0300, a critical vulnerability in Palo Alto Networks Cloud NGFW that allows remote code execution. The flaw impacts a core security control layer, meaning attackers can bypass protections and execute arbitrary commands on affected systems. This puts network traffic, sensitive data, and downstream systems at immediate risk.
CVE-2026-0300 has a CVSS score of 9.3, which is Critical severity. Active exploitation has been confirmed, indicating that attackers are already leveraging this vulnerability in real-world environments. This significantly increases urgency, especially for organizations relying on Cloud NGFW to secure internet-facing infrastructure.
Key Details
- Affected Product
- Paloaltonetworks Pan-os
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-787