CVE-2026-0300
Known exploited · CISA KEV
EPSS 32% (98th percentile).
CISA federal remediation date May 9 · date passed
Vulnerabilities & Exploits
This is not just a firewall problem. A PAN-OS captive-portal buffer overflow can give an unauthenticated attacker root code execution on Siemens RUGGEDCOM APE1808 devices, so a perimeter surface becomes a foothold inside critical manufacturing networks.
CISA maps CVE-2026-0300 to Siemens RUGGEDCOM APE1808, all versions. Siemens says fixes are still being prepared, and CISA lists mitigations that keep the User-ID Authentication Portal or response pages constrained to trusted internal use.
The risk stays live until those controls are in place. An overdue KEV entry and a sharp EPSS rise point to exposed devices that may remain reachable on operational sites even without a vendor patch.
1 source · May 19
Known exploited · CISA KEV
EPSS 32% (98th percentile).
CISA federal remediation date May 9 · date passed
CISA Advisories
Siemens RUGGEDCOM APE1808 Devices | CISA
Siemens RUGGEDCOM APE1808 Devices Summary A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series…
originalVendor digest: Palo Alto Networks
Part of the PlainSec briefing for 2026-05-19
Every edition of this story: Critical Manufacturing Gear Exposed by PAN-OS Flaw