Zero-dayMay 6, 2026
Palo Alto Networks warns of firewall RCE zero-day exploited in attacks
Palo Alto Networks reports critical PAN-OS User-ID portal RCE zero-day under active exploitation.
Vendor Watch
Run Palo Alto Networks?
Get an email when a reviewed story names Palo Alto Networks, usually within the hour.
Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch worksPrivacy
Summary
Palo Alto Networks disclosed a critical-severity remote code execution vulnerability in the PAN-OS User-ID Authentication Portal that is currently being exploited in active attacks. The flaw remains unpatched at the time of disclosure. This represents an immediate threat to organizations running affected Palo Alto Networks firewalls.
Entities
Palo Alto Networks (vendor)PAN-OS (product)User-ID Authentication Portal (product)