Palo Alto Networks disclosed that threat actors may have attempted to exploit a critical security vulnerability as early as April 9, 2026. The vulnerability, CVE-2026-0300 (CVSS score: 9.3/8.7), is a buffer overflow flaw in the User-ID Authentication Portal service of PAN-OS software that could allow unauthenticated attackers to gain unauthorized access.
