Mark RadarMARK RADAR
EN
Event File AI Cyberattacks

Nation-State Hackers Exploit Zero-Day Flaw in Palo Alto Networks Firewalls

1 reports · First detected 2026-05-07 · Last active 2026-05-07

Palo Alto Networks’ PAN-OS is widely used to protect enterprise and government network perimeters. CVE-2026-0300 allows attackers to gain root privileges and execute code through an authentication portal, effectively bypassing a core layer of defense and posing a major risk to PA-Series and VM-Series firewalls.

As of July 20, 2026, Palo Alto Networks said the zero-day vulnerability had been actively exploited by a nation-state hacking group. After breaching targets, the attackers deployed network tunneling tools and conducted reconnaissance of victims’ internal networks. Affected products include physical PA-Series and virtualized VM-Series firewalls.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)