CVE-2026-0257
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
Exploited in the wild. In CISA KEV since 2026‑05‑29. A vendor fix is available.
What to do
The vendor has published a fix. Version details are below where the sources state them.
Steps
Written by AI from the record- Check whether your firewalls have PAN-OS installed and whether GlobalProtect “portal” and/or “gateway” are enabled.
- Identify your exact PAN-OS version (and whether you use GlobalProtect authentication override cookies).
- Upgrade PAN-OS to a fixed release: 12.1.7, 12.1.4-h6, 11.2.12, 11.2.10-h7, 11.2.7-h14, 11.2.4-h17, 11.1.15, 11.1.13-h5, 11.1.10-h25, 11.1.7-h6, 11.1.6-h32, 11.1.4-h33, or 10.2.18-h6 (and the other fixed versions listed for your branch).
- For Prisma Access, upgrade to 10.2.10-h36 or 11.2.7-h13.
- If you cannot patch right away, follow Palo Alto Networks’ vendor mitigations/workarounds from the vendor advisory and disable or restrict any exposed GlobalProtect interfaces as directed.
- Validate after changes that GlobalProtect portal/gateway authentication behavior is back to normal and plan for re-authentication if you use authentication override cookies.
What it is
From the CVE record
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.
In plain language
Written by AI from the recordCVE-2026-0257 is a serious GlobalProtect login-bypass flaw in PAN-OS that lets attackers connect a fake VPN session without authenticating; if you run PAN-OS GlobalProtect (portal or gateway), you should treat this as urgent and patch immediately.
CVE-2026-0257 is a GlobalProtect authentication bypass in PAN-OS (GlobalProtect portal and gateway) that allows an attacker to bypass authentication and establish an unauthorized VPN connection over the network; CISA added it to KEV with active exploitation reported.
If you're affected
- Unauthorized VPN access
- Security controls bypassed
- Possible data theft risk
- Incident response disruption
Exploitation
Where each signal puts this CVE on the scale from published to confirmed exploited.
- CISA KEV
Listed as exploited in the wild since 2026-05-29.
US federal agencies must remediate by 2026-06-01.
Known use in ransomware campaigns.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Public exploits
0 sources with a proof of concept or module.
Exploit links, PoCs and Metasploit modules after sign-in- EPSS
97% chance of exploitation activity in the next 30 days, which ranks it in the 99th percentile of scored CVEs.
Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.
Lifecycle
18 events over 84 days, from the signal feeds we watch.
- Analysis publishedThe guardian is the gateway: 2026's exploited-bug list is a map of the security products we trusted
- EPSS band changehigh → criticalepss band change
- EPSS band changemoderate → high
- EPSS band changemoderate → high
- EPSS band changemoderate → high
- OpenVAS check added
Affected products
Technical detail
CVSS 3.1 vector
Open in the CVSS calculatorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Scored 9.1 by NVD.
How it is reached
- Attack Vector NetworkExploitable remotely over the network without any special conditions
- Attack Complexity LowNo special conditions — the attack can be reliably reproduced
- Privileges Required NoneNo authentication required — anyone can exploit this
- User Interaction NoneNo user interaction needed — fully automated exploitation
Scope
- Scope UnchangedImpact is limited to the vulnerable component itself
Impact if exploited
- Confidentiality HighTotal information disclosure — all data in the component is compromised
- Integrity HighTotal loss of integrity — attacker can modify any data in the component
- Availability NoneNo availability impact
Weaknesses
Sources
References in the record
- security.paloaltonetworks.com/CVE-2026-0257
- cert-portal.siemens.com/productcert/html/ssa-967325.html
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-0257
And 34 more references. See all after sign-in
In the news
All news- Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
- Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
- Малварь ChocoPoC распространяется под видом фальшивых эксплоитов
- В фокусе RVD: трендовые уязвимости июня
- New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos
- ChocoPoc malware delivered via trojanized exploits on GitHub
- New ChocoPoC malware targets researchers via trojanized PoC exploits
- Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw
- Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257
- 1st June – Threat Intelligence Report
Watch the software you run.
My Stack ranks new CVEs for your products by real-world exploitation, so the next exploited one reaches you without reading every advisory.
We'll flag the next CVE, public exploit or patch for Cloud NGFW, not every advisory. This one: actively exploited.
A free account adds
- The full version matrix and every affected product
- Exploit links, proofs of concept and Metasploit modules
- Email alerts for the products you watch
- The same data over REST API, MCP and CLI