Serial number: AV26-425
Date: May 6, 2026
On May 5, 2026, Palo Alto Networks published a security advisory to address critical vulnerabilities in the following products:
- PAN-OS 12.1 – versions prior to 12.1.4-h5
- PAN-OS 12.1 – versions prior to 12.1.7
- PAN-OS 11.2 – multiple versions
- PAN-OS 11.1 – multiple versions
- PAN-OS 10.2 – multiple versions
Palo Alto has received reports that CVE-2026-0300 is being actively exploited.
Update 1
On May 6, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-0300 to their Known Exploited Vulnerabilities (KEV) Database.
The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates, when available.
