Earlier this month a new vulnerability, CVE-2026-0300, was discovered in Palo Alto’s Authentication Portal. This vulnerability could allow an unauthenticated attacker to execute arbitrary code as the root user.
If the authentication portal is only exposed to internal and trusted networks, the risk is reduced; however, any authentication portal exposed to the wider internet could allow an attacker to gain root access to the device.
Per Palo Alto this issue affects PA-Series and VM-Series firewalls with User-ID authentication Portal. Limited exploitation has been reported.
What to Do Now
Palo Alto Networks has released fixes in recent PAN-OS updates. They strongly recommend that all affected organizations implement them immediately.