CVE-2026-0257
published 2026-05-13CVE-2026-0257: Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security…
PriorityP1100critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2026-06-01
Exploited in the wild
EPSS
86.68%
99.7th percentile
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.
Panorama and Cloud NGFW are not impacted by these issues.
Affected
169 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| palo_alto_networks | pan-os | >= 10.2.0 < 10.2.18-h6, 10.2.16-h7, 10.2.13-h21, 10.2.10-h36, 10.2.7-h34 | 10.2.18-h6, 10.2.16-h7, 10.2.13-h21, 10.2.10-h36, 10.2.7-h34 |
| palo_alto_networks | pan-os | >= 11.1.0 < 11.1.15, 11.1.13-h5, 11.1.10-h25, 11.1.7-h6, 11.1.6-h32, 11.1.4-h33 | 11.1.15, 11.1.13-h5, 11.1.10-h25, 11.1.7-h6, 11.1.6-h32, 11.1.4-h33 |
| palo_alto_networks | pan-os | >= 11.2.0 < 11.2.12, 11.2.10-h7, 11.2.7-h14, 11.2.4-h17 | 11.2.12, 11.2.10-h7, 11.2.7-h14, 11.2.4-h17 |
| palo_alto_networks | pan-os | >= 12.1.0 < 12.1.7, 12.1.4-h6 | 12.1.7, 12.1.4-h6 |
| palo_alto_networks | prisma_access | >= 10.2.0 < 10.2.10-h36 | 10.2.10-h36 |
| palo_alto_networks | prisma_access | >= 11.2.0 < 11.2.7-h13 | 11.2.7-h13 |
| paloalto | cloud_ngfw | — | — |
| paloalto | pan-os | — | — |
| paloalto | prisma_access | — | — |
| paloaltonetworks | pan-os | < 10.2.7 | 10.2.7 |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
| paloaltonetworks | pan-os | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Search GlobalProtect logs for successful gateway-connected events from the listed attacker IPs (pre-PoC release, before May 29, 2026) ↗
- →Search GlobalProtect logs for successful gateway-connected events matching PoC hard-coded client config: endpoint_os_version = 'Microsoft Windows 10 Pro 64-bit' AND source_user_info.domain = empty ↗
- →Alert on GlobalProtect cookie-based authentication (auth method = 'Cookie') to local admin account, especially from non-corporate IP ranges — indicative of forged authentication override cookie abuse ↗
- →Monitor GlobalProtect logs for auth method 'Cookie' with login to 'admin' account and gateway-auth event type, as seen in observed exploitation log entries ↗
- →Exploitation involves POST requests to /ssl-vpn/login.esp with forged values in the portal-userauthcookie or portal-prelogonuserauthcookie HTTP form fields — monitor web/proxy logs for these POST requests from unexpected sources ↗
- ·Vulnerability is only exploitable when GlobalProtect authentication override cookies are enabled AND the portal/gateway certificate is shared with the HTTPS service — devices without this configuration are not vulnerable ↗
- ·Panorama and Cloud NGFW are explicitly not impacted by CVE-2026-0257 ↗
- ·Cloud Authentication Service (CAS) being disabled was observed on all impacted customer devices — this configuration detail may be relevant to scoping exposure ↗
- ·Authentication override cookie feature is NOT enabled by default — only explicitly configured devices are at risk ↗
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv4.07.8HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:Red
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
cisa·2026-05-29·CVSS 7.8
CVE-2026-0257 [HIGH] CWE-565 Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
Vulnerability: Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
Affected: Palo Alto Networks PAN-OS
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://security.paloaltonetworks.com/CVE-2026-0257 ; https://nvd.nist.gov/vuln/detail/CVE-2026-0257
Remediation Due Date: 2026-06-01
Palo Alto
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
vendor_paloalto·CVSS 4.7
CVE-2026-0257 [MEDIUM] CWE-565 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.
Panorama and Cloud NGFW are not impacted by these issues.
Affected products: Cloud NGFW, PAN-OS, Prisma Access
Solution: VERSION MINOR VERSION SUGGESTED SOLUTION
Cloud NGFW All No action needed.
PAN-OS 12.1 12.1.5 through 12.1.6 Upgrade to 12.1.7 or later.
12.1.2 through 12.1.4-h* Upgrade to 12.1.4-h6 or 12.1.7 or later.
PAN-OS 11.2 11.2.11 or later Upgrade to 11.2.12 or later.
11.2.8 through 11.2.10-h* Upgrade to 11.2.10-h7 or 11.2.12 or later.
11.2.5 through 11.2.7-h* Upgrade to 11.2.7-h14 or 11.2.12 or later.
11.
GHSA
GHSA-jqxw-84hx-6qj5: Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass sec
ghsa_unreviewed·2026-05-13
CVE-2026-0257 [MEDIUM] CWE-565 GHSA-jqxw-84hx-6qj5: Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass sec
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.
Panorama and Cloud NGFW are not impacted by these issues.
VulDB
Palo Alto Cloud NGFW/PAN-OS/Prisma Access GlobalProtect Portal cookie validation (EUVD-2026-30104)
vuldb·2026-05-13·CVSS 4.7
CVE-2026-0257 [MEDIUM] Palo Alto Cloud NGFW/PAN-OS/Prisma Access GlobalProtect Portal cookie validation (EUVD-2026-30104)
A vulnerability described as critical has been identified in Palo Alto Cloud NGFW, PAN-OS and Prisma Access. This affects an unknown part of the component GlobalProtect Portal. Such manipulation leads to cookies without validation.
This vulnerability is uniquely identified as CVE-2026-0257. The attack can be launched remotely. No exploit exists.
VulnCheck
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
vulncheck·2026·CVSS 7.8
CVE-2026-0257 [HIGH] CWE-565 Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.
Affected: Palo Alto Networks PAN-OS
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.rapid7.com/blog/post/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257/
Remediation Due: 2026-06-01
No detection rules found.
Nuclei
Palo Alto Networks PAN-OS - Authentication Bypass
nuclei·CVSS 7.8
CVE-2026-0257 [HIGH] Palo Alto Networks PAN-OS - Authentication Bypass
Palo Alto Networks PAN-OS - Authentication Bypass
Palo Alto Networks PAN-OS contains an authentication bypass caused by flaws in the GlobalProtect portal and gateway, letting attackers establish unauthorized VPN connections, exploit requires network access to the portal or gateway.
Template:
id: CVE-2026-0257
info:
name: Palo Alto Networks PAN-OS - Authentication Bypass
author: dhiyaneshdk,sfewer-r7
severity: critical
description: |
Palo Alto Networks PAN-OS contains an authentication bypass caused by flaws in the GlobalProtect portal and gateway, letting attackers establish unauthorized VPN connections, exploit requires network access to the portal or gateway.
impact: |
Attackers can bypass authentication to establish unauthorized VPN connections, potentially gaining network access.
r
Wiz
Agentless Threat Detection: Illuminating Cloud Blind Spots
blogs_wiz·2026-07-21·CVSS 9.8
CVE-2026-24858 [CRITICAL] Agentless Threat Detection: Illuminating Cloud Blind Spots
Virtual appliances play a critical role in cloud networks, providing services such as firewalls, secure gateways, and VPN connectivity. Yet, because they operate as "black boxes" that don't support traditional EDR agents, they have historically been a massive visibility gap for security teams. Over the past months, Wiz’s Agentless Workload Detection has fundamentally changed this pattern. Not only does it provide critical visibility into virtual appliances, but it also gives our research and IR teams the context needed to investigate activity associated with high-profile threat actors..This allows us to detect and analyze a wide array of sophisticated attacks, all without the need for agents.
In this blog post, we’ll show you a subset of the unique value this new capability has unlocked,
Hackernews
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
blogs_hackernews·2026-07-21·CVSS 9.1
CVE-2026-0257 [CRITICAL] Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments.
Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software.
Successful exploitation of the flaw allows unauthenticated remote attackers to sidestep authentication and establish VPN
Unit42
Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
blogs_unit42·2026-07-17·CVSS 7.5
CVE-2025-40947 [HIGH] Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
## Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
Emmanuel Zhou
Adam Robbie
Rick Wyble
Miguel Pereira
Published: July 17, 2026
Threat Research
Vulnerabilities
Command injection
CVE-2025-40947
CVE-2025-40948
CVE-2025-40949
Exploit Chain
Privilege escalation
Rox II OT switches
## Executive Summary
We conducted this research in close partnership with Siemens, reflecting our shared commitment to advancing the security and resilience of critical infrastructure.
This report details a critical, chained exploit comprising three zero-day vulnerabilities (CVE-2025-40948, CVE-2025-40947, and CVE-2025-40949) discovered in Siemens ROX II operational technology (OT) switches. Successful exploitation of this chain would allow an attacker to achieve full privilege escal
Hackernews
New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos
blogs_hackernews·2026-07-02
CVE-2025-64446 New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos
Attackers are hiding a data-stealing trojan inside fake exploit code aimed at the people who hunt bugs for a living. The malware, called ChocoPoC , travels in Python proof-of-concept (PoC) repositories on GitHub that claim to exploit hot new CVEs.
Run one, and it quietly lifts your saved passwords, browser cookies, and files, then hands the attacker a shell on your machine. YesWeHack and Sekoia published their joint findings on July 1 and warned that, as of that report, the malware and its servers were still live, so do not run any of these PoCs.
Hackernews
Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw
blogs_hackernews·2026-06-15·CVSS 9.1
CVE-2026-0257 [CRITICAL] Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw
Palo Alto Networks has revealed that it has observed "active exploitation" of a recently disclosed PAN-OS vulnerability by an unknown threat actor to obtain unauthorized access to GlobalProtect portals.
The vulnerability in question is CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software that could be exploited by bad actors to set up VPN connections.
According to the network security company, the security defect could be exploited by a bad actor to bypass security controls and ini
Rapid7
Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)
blogs_rapid7·2026-06-08·CVSS 8.6
CVE-2026-50751 [HIGH] Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)
## Overview
On June 8, 2026, Check Point published a security advisory for CVE-2026-50751 , a critical authentication bypass vulnerability affecting Check Point Remote Access VPN, Mobile Access, and Spark Firewall products. The vulnerability affects deployments configured to use the deprecated IKEv1 key exchange protocol where gateways accept legacy Remote Access clients and do not require a machine certificate for connections.
CVE-2026-50751, classified as improper authentication ( CWE-287 ), has a CVSS score of 9.3. The vulnerability stems from a logic flow weakness in how Remote Access and Mobile Access components validate certificates during IKEv1 key exchange; successful exploitation allows an unauthenticated attacker to establish a VPN session without providing valid credentials. P
Unit42
Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257
blogs_unit42·2026-06-05·CVSS 7.8
CVE-2026-0257 [HIGH] Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257
## Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257
Andy Piazza
Unit 42
Published: June 5, 2026
High Profile Threats
Vulnerabilities
CVE-2026-0257
Vulnerability
Palo Alto Networks Unit 42 has observed active exploitation of PAN-OS vulnerability CVE-2026-0257 by an unidentified threat actor attempting to access GlobalProtect. This security flaw involves an authentication bypass in the portal and gateway components of vulnerable versions of PAN-OS ® software, which could allow unauthorized attackers to circumvent security controls and initiate VPN connections. This CVE was added to the Known Exploited Vulnerability (KEV) catalog on May 29.
No post-access behavior or lateral movement has been identified as of this time. Only a small portion of the probed devices actually es
Rapid7
How the “Swiss Cheese” model can help you choose the right MDR provider
blogs_rapid7·2026-06-04
CVE-2026-0257 How the “Swiss Cheese” model can help you choose the right MDR provider
Not all managed detection and response (MDR) solutions are equal. Finding the differences between vendors can be quite hard, and then understanding how those differences impact your business can be even harder. For instance, you may come across an MDR provider whose pricing is based on how much data you ingest rather than the number of assets you protect.
Ingestion-based solutions have the potential to be more cost effective if you're selective about what security telemetry you ingest – but then who analyzes the impact of the logs you're leaving out until they're needed?
Or, consider an MDR solution that's more EDR with just a few additional log sources. For some organizations this is a perfectly optimal fit. But, how often are logging blind spots reviewed and accepted as a risk? In my e
Hackernews
⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More
blogs_hackernews·2026-06-01·CVSS 7.8
CVE-2026-0257 [HIGH] ⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More
Monday hit like a cron job with anger issues.
A busted auth path here, a repo-side faceplant there, some "patched-ish" thing already getting chewed on in the wild, and then the usual bonus round: poisoned dev tools, sketchy forum chatter, phishing kits pretending to be productivity, and AI lowering the bar for people who already thought 'curl | sh' had a personality.
The vibe is simple: old bugs, new wrappers, faster abuse. Patch the obvious crap first. Then read the rest.
## ⚡ Threat of the Week
PAN-OS GlobalProtect Authenticati
Checkpoint
1st June – Threat Intelligence Report
blogs_checkpoint·2026-06-01
CVE-2026-48131 1st June – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 1st June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 1st June, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Carnival Corporation, a global cruise line operator, has confirmed a data breach affecting nearly 6 million people after attackers used social engineering to compromise an employee account. Exposed information may include names, contact details, dates of birth, and government identification numbers.
Charter Communications, a US t
Bleepingcomputer
Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks
blogs_bleepingcomputer·2026-05-30·CVSS 7.8
CVE-2026-0257 [HIGH] Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks
## Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks
## Lawrence Abrams
Palo Alto Networks is warning that hackers are now exploiting a PAN-OS GlobalProtect authentication bypass flaw, tracked as CVE-2026-0257, in attacks attempting to breach corporate networks.
The company fixed the CVE-2026-0257 flaw earlier this month, warning that it could be used to establish unauthorized VPN connections on the device.
"GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection," reads Palo Alto's advisory .
The flaw received a Medium severity rating because it requires devices to be configured with authentication override cookies enabled and a specific certificate con
Hackernews
PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation
blogs_hackernews·2026-05-30·CVSS 7.8
CVE-2026-0257 [HIGH] PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation
Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in the wild.
The vulnerability, tracked as CVE-2026-0257 (CVSS score: 7.8), refers to a case of authentication bypass that could be exploited by bad actors to set up VPN connections.
"Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allow the attacker to bypass security restrictions and establish an unauthorized VPN conn
Rapid7
Rapid7 Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257)
blogs_rapid7·2026-05-29·CVSS 7.8
CVE-2026-0257 [HIGH] Rapid7 Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257)
## Overview
On May 13, 2026, Palo Alto Networks published a security advisory for CVE-2026-0257, a medium severity authentication bypass affecting PAN-OS and Prisma Access when a specific configuration is present. Successful exploitation of this vulnerability allows a remote unauthenticated attacker to successfully establish a VPN connection through the GlobalProtect gateway of an affected appliance.
Rapid7 MDR identified successful exploitation across numerous customers, however we did not observe any indication of successful lateral movement from the devices. The earliest date for observed exploitation was May 17, 2026. As of May 29, 2026, this vulnerability has been added to the CISA KEV.
While the assigned CVSSv4 score indicates a medium severity, due to the circumstances surroundin
2026-05-13
Published
2026-05-29
Added to CISA KEV
Exploited in the wild