cbcvebase.
CVE-2026-0257
published 2026-05-13

CVE-2026-0257: Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security…

PriorityP1100critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2026-06-01
Exploited in the wild
EPSS
86.68%
99.7th percentile
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

Affected

169 ranges· showing 25
VendorProductVersion rangeFixed in
palo_alto_networkspan-os>= 10.2.0 < 10.2.18-h6, 10.2.16-h7, 10.2.13-h21, 10.2.10-h36, 10.2.7-h3410.2.18-h6, 10.2.16-h7, 10.2.13-h21, 10.2.10-h36, 10.2.7-h34
palo_alto_networkspan-os>= 11.1.0 < 11.1.15, 11.1.13-h5, 11.1.10-h25, 11.1.7-h6, 11.1.6-h32, 11.1.4-h3311.1.15, 11.1.13-h5, 11.1.10-h25, 11.1.7-h6, 11.1.6-h32, 11.1.4-h33
palo_alto_networkspan-os>= 11.2.0 < 11.2.12, 11.2.10-h7, 11.2.7-h14, 11.2.4-h1711.2.12, 11.2.10-h7, 11.2.7-h14, 11.2.4-h17
palo_alto_networkspan-os>= 12.1.0 < 12.1.7, 12.1.4-h612.1.7, 12.1.4-h6
palo_alto_networksprisma_access>= 10.2.0 < 10.2.10-h3610.2.10-h36
palo_alto_networksprisma_access>= 11.2.0 < 11.2.7-h1311.2.7-h13
paloaltocloud_ngfw
paloaltopan-os
paloaltoprisma_access
paloaltonetworkspan-os< 10.2.710.2.7
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os

Detection & IOCsextracted from sources · hover to see the quote

url/ssl-vpn/login.esp
otherportal-userauthcookie
otherportal-prelogonuserauthcookie
process/usr/local/bin/gpsvc
  • Search GlobalProtect logs for successful gateway-connected events from the listed attacker IPs (pre-PoC release, before May 29, 2026)
  • Search GlobalProtect logs for successful gateway-connected events matching PoC hard-coded client config: endpoint_os_version = 'Microsoft Windows 10 Pro 64-bit' AND source_user_info.domain = empty
  • Alert on GlobalProtect cookie-based authentication (auth method = 'Cookie') to local admin account, especially from non-corporate IP ranges — indicative of forged authentication override cookie abuse
  • Monitor GlobalProtect logs for auth method 'Cookie' with login to 'admin' account and gateway-auth event type, as seen in observed exploitation log entries
  • Exploitation involves POST requests to /ssl-vpn/login.esp with forged values in the portal-userauthcookie or portal-prelogonuserauthcookie HTTP form fields — monitor web/proxy logs for these POST requests from unexpected sources
  • ·Vulnerability is only exploitable when GlobalProtect authentication override cookies are enabled AND the portal/gateway certificate is shared with the HTTPS service — devices without this configuration are not vulnerable
  • ·Panorama and Cloud NGFW are explicitly not impacted by CVE-2026-0257
  • ·Cloud Authentication Service (CAS) being disabled was observed on all impacted customer devices — this configuration detail may be relevant to scoping exposure
  • ·Authentication override cookie feature is NOT enabled by default — only explicitly configured devices are at risk

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv4.07.8HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:Red
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.