Back to Feed
Zero-dayMay 6, 2026

Palo Alto Networks warns of firewall RCE zero-day exploited in attacks

Palo Alto Networks reports critical PAN-OS User-ID portal RCE zero-day under active exploitation.

Vendor Watch

Run Palo Alto Networks?

Get an email when a reviewed story names Palo Alto Networks, usually within the hour.

Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch worksPrivacy

Summary

Palo Alto Networks disclosed a critical-severity remote code execution vulnerability in the PAN-OS User-ID Authentication Portal that is currently being exploited in active attacks. The flaw remains unpatched at the time of disclosure. This represents an immediate threat to organizations running affected Palo Alto Networks firewalls.

Entities

Palo Alto Networks (vendor)PAN-OS (product)User-ID Authentication Portal (product)