CVE-2026-0300: If your Palo Alto User-ID Authentication Portal is internet-exposed, lock it down now — patches start May 13
A critical PAN-OS zero-day, CVE-2026-0300, is being actively exploited but only when Palo Alto Networks’ User-ID Authentication Portal is reachable from untrusted networks. Patches begin rolling out on May 13, 2026; until your appliances are updated, restricting or disabling the portal is the practical defense that changes your immediate risk profile. Portal-exposed versus default deployments: […]