Palo Alto Networks PAN-OS Authentication Bypass Zero-Day | MSSP Advisory
Critical
DateMay 7, 2026
📋Executive Summary
Palo Alto Networks confirmed that suspected state-sponsored attackers exploited CVE-2024-0012, a critical authentication bypass vulnerability in PAN-OS firewalls, for nearly a month before discovery. The zero-day allows remote attackers to gain administrator privileges on affected firewall management interfaces without authentication. Palo Alto released emergency patches and provided threat prevention signatures to block exploitation attempts.
⚠️Why It Matters for MSSPs
Your clients trust their Palo Alto firewalls as perimeter defense, and this zero-day gave attackers admin access to reconfigure rules, disable logging, and create backdoors for nearly 30 days undetected. If you manage Palo Alto devices for clients or rely on them in your own infrastructure, you face direct compromise risk plus the liability of advising clients who got breached through their supposedly secure firewalls.
📬
Get notified when client-ready advisories like this are published each week.
Join the MSSP Watchlist →🏷️Threat Category
Zero-Day
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.