Palo Alto Networks addressed a critical flaw in the operating system (PANOS) that powers its next-generation firewalls that could allow unauthenticated network-based attackers to bypass authentication. The vulnerability has been rated as critical severity and received a CVSS 3.x base score of 10. The company confirmed that the vulnerability cannot be exploited if SAML is not used for authentication and if the Validate Identity Provider Certificate option is enabled (checked) in the SAML Identity Provider Server Profile.”]
Source: https://securityaffairs.co/wordpress/105351/hacking/critical-flaw-firewall-pan-os.html

