cbcvebase.
CVE-2026-0257
published 2026-05-13

CVE-2026-0257: Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security…

high7.8CVSS 4.0
AVNACLATNPRNUINVCLVINVANSCHSIHSANEACRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUNRAVDREMURed
KEVEXPLOIT
CISA Known Exploited Vulnerabilitydue 2026-06-01
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

Affected

54 ranges· showing 25
VendorProductVersion rangeFixed in
palo_alto_networkspan-os>= 10.2.0 < 10.2.18-h6, 10.2.16-h7, 10.2.13-h21, 10.2.10-h36, 10.2.7-h3410.2.18-h6, 10.2.16-h7, 10.2.13-h21, 10.2.10-h36, 10.2.7-h34
palo_alto_networkspan-os>= 11.1.0 < 11.1.15, 11.1.13-h5, 11.1.10-h25, 11.1.7-h6, 11.1.6-h32, 11.1.4-h3311.1.15, 11.1.13-h5, 11.1.10-h25, 11.1.7-h6, 11.1.6-h32, 11.1.4-h33
palo_alto_networkspan-os>= 11.2.0 < 11.2.12, 11.2.10-h7, 11.2.7-h14, 11.2.4-h1711.2.12, 11.2.10-h7, 11.2.7-h14, 11.2.4-h17
palo_alto_networkspan-os>= 12.1.0 < 12.1.7, 12.1.4-h612.1.7, 12.1.4-h6
palo_alto_networksprisma_access>= 10.2.0 < 10.2.10-h3610.2.10-h36
palo_alto_networksprisma_access>= 11.2.0 < 11.2.7-h1311.2.7-h13
paloaltocloud_ngfw
paloaltopan-os
paloaltoprisma_access
paloaltonetworkspan-os< 10.2.710.2.7
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os
paloaltonetworkspan-os

CVSS provenance

nvdv4.07.8HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:Red
vulncheck7.8HIGH
cisa7.8HIGH