INTEL_REPORT
Palo Alto Networks Unit 42 · published 5/7/2026, 12:00:53 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution Unit 42 details CVE-2026-0300, a buffer overflow vulnerability in the PAN-OS User-ID Authentication Portal. Read now for details. The post Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution appeared first on Unit 42 . Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution Me…
https://unit42.paloaltonetworks.com/captive-portal-zero-day
sha256:9495d60b4df41894492a6f739e06d5be4e6ee26a6a16b6750af063853967ac77
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| Open → |
| sha256 | e11f69b49b6f2e829454371c31ebf86893f82a042dae3f2faf63dcd84f97a584 | Open → |
| cve | CVE-2026-0300 | Open → |
| cve | CVE-2026-1731 | Open → |
| cve | CVE-2026-31431 | Open → |
| cve | CVE-2023-33538 | Open → |
| cve | CVE-2026-1281 | Open → |
| cve | CVE-2026-1340 | Open → |
| cve | CVE-2025-0921 | Open → |
| cve | CVE-2025-14847 | Open → |
| cve | CVE-2025-23304 | Open → |
| cve | CVE-2026-22584 | Open → |
| cve | CVE-2025-55182 | Open → |
| cve | CVE-2025-66478 | Open → |