Security Advisories

Tailwind's analysis of high-impact CVEs and disclosure events we're tracking for our customers.

panw-cve-og.png
Security Advisory · May 13, 2026

Four PAN-OS CVEs, One Hotfix: The May 13 Bundle Closes May 5 Too

The May 13 PAN-OS hotfix builds also fix CVE-2026-0300, the actively-exploited May 5 RCE. One install per device closes four CVEs. Why CAS bypass is the one to escalate first, and how to retire the May 5 mitigations in the same change.

Bill Church Bill Church
Dirty Frag Advisory Image
Security Advisory · May 8, 2026

Dirty Frag: what to do before your distro ships a kernel update

Operational guidance on Dirty Frag — CVE-2026-43284 (IPsec ESP) and CVE-2026-43500 (RxRPC), the second LPE chain in nine days in the same bug class as Copy Fail. Why your Copy Fail mitigation does not cover it, and the three-module modprobe deny to deploy now.

Bill Church Bill Church
CVE-2026-0300 Advisory
Security Advisory · May 6, 2026

CVE-2026-0300: The Captive Portal You Didn't Know You Had

Operational guidance on CVE-2026-0300, the unauthenticated PAN-OS Authentication Portal RCE under active exploitation. What to check today, what the hotfix calendar actually looks like, and the legacy-naming gotcha keeping ops teams from realizing they're exposed.

Bill Church Bill Church
Engineer's workbench
Security Advisory · April 30, 2026

Copy Fail: Patches Are Coming. Here's What to Do Until They Land.

732 bytes of Python is enough to root every major Linux distro shipped since 2017. That is the short version of CVE-2026-31431 ("Copy Fail"), disclosed this week by Theori. Ubuntu, RHEL, Amazon Linux, SUSE, kernels 6.12 through 6.18.

Bill Church Bill Church