PAN-OS Captive Portal RCE: State-Sponsored Exploitation Hits 5,800+ Exposed Firewalls

State-sponsored exploitation of a PAN-OS captive portal RCE has reached more than 5,800 exposed firewalls.

State-sponsored exploitation of a PAN-OS captive portal RCE has reached more than 5,800 exposed firewalls.

  • The captive portal is the remote-code-execution surface in this campaign.
  • Activity is attributed to state-sponsored exploitation.
  • A large population of internet-exposed firewalls is affected.

This briefing is part of SecureW2’s Cybersecurity Intelligence series, which tracks identity, certificate, and network-security events for the teams who have to respond to them.