Palo Alto Networks PAN-OS Vulnerability
Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.
CVSS Score
9.8
CRITICAL
Published
06 May 2026 00:00
Modified
N/A
Vendor
Palo Alto Networks
Product
PAN-OS
Source
CIRCL
Affected Versions
Fix
Vendor Patch / Mitigation Available
Weaknesses (CWE)
CWE-787
Affected Systems
Palo Alto Networks
PAN-OS
Palo Alto Networks
PAN-OS
External Links
KEV Status
Known Exploited Vulnerability