Palo Alto Networks PAN-OS Critical RCE Exploited | MSSP Advisory

CriticalCredible Report
DateMay 7, 2026
📋Executive Summary
Palo Alto Networks disclosed a critical vulnerability in PAN-OS with active exploitation, scoring CVSS 9.3 when User-ID Authentication Portal faces untrusted networks. Unauthenticated attackers gain arbitrary code execution with root privileges on PA-Series and VM-Series firewalls. The company confirms attacks are happening now.
⚠️Why It Matters for MSSPs
Your MSSP infrastructure likely runs behind Palo Alto firewalls that could be compromised with root access, exposing every client network you manage through established VPN tunnels and trust relationships. Client environments protected by these same firewall models become sitting ducks, and if breaches occur through compromised perimeter security you recommended, contract renewals become conversations about liability.
📬

Get notified when client-ready advisories like this are published each week.

Join the MSSP Watchlist →
🏷️Threat Category
Zero-Day

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.