CVE-2026-0300 – Palo Alto Cloud NGFW

CVSS 9.8 CRITICAL

“When your firewall is vulnerable, your entire network is exposed.”

This patch addresses CVE-2026-0300, a critical vulnerability in Palo Alto Networks Cloud NGFW that allows remote code execution. The flaw impacts a core security control layer, meaning attackers can bypass protections and execute arbitrary commands on affected systems. This puts network traffic, sensitive data, and downstream systems at immediate risk.

CVE-2026-0300 has a CVSS score of 9.3, which is Critical severity. Active exploitation has been confirmed, indicating that attackers are already leveraging this vulnerability in real-world environments. This significantly increases urgency, especially for organizations relying on Cloud NGFW to secure internet-facing infrastructure.

Key Details

Affected Product
Paloaltonetworks Pan-os
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-787
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.