PAN-OS Captive Portal RCE: State-Sponsored Exploitation Hits 5,800+ Exposed Firewalls
CVE-2026-0300
5,800+
EXPOSED
Threat Intelligence
Threat Intelligence

PAN-OS Captive Portal RCE: State-Sponsored Exploitation Hits 5,800+ Exposed Firewalls

State-sponsored exploitation of a PAN-OS captive portal RCE has reached more than 5,800 exposed firewalls.
S2
SecureW2 Threat Intelligence
May 25, 2026
· 1 min read

State-sponsored exploitation of a PAN-OS captive portal RCE has reached more than 5,800 exposed firewalls.

  • The captive portal is the remote-code-execution surface in this campaign.
  • Activity is attributed to state-sponsored exploitation.
  • A large population of internet-exposed firewalls is affected.

This briefing is part of SecureW2’s Cybersecurity Intelligence series, which tracks identity, certificate, and network-security events for the teams who have to respond to them.

S2

SecureW2 Threat Intelligence

SIGNAL's threat-intelligence desk tracks identity, certificate, and network-security events and translates them for the teams who have to respond. Reporting is independent of product marketing.

Keep Reading

The May 2026 AI Agent Framework RCE Wave: When Prompts Become Shells
BadHostCVE-2026-25592PraisonAI

PROMPTS
BECOME SHELLS

Cisco ISE Flaw: Read-Only Admin to Root, No Workarounds
CVE-2026-20147

READ-ONLY
TO ROOT

Salt Typhoon's Telecom Infiltration: A Two-Year Campaign in the Backbone
Salt Typhoon

TWO YEARS
INSIDE

Get the brief before the breach.

SIGNAL decodes the week’s identity, certificate, and network-security events — for the IT and security teams who have to respond to them.

Weekly. No vendor fluff. Unsubscribe anytime.