← Vulnerability feed

Vulnerability record · CVE-2026-0257 · published 13 May 2026

CVE-2026-0257: PAN-OS GlobalProtect authentication bypass via unvalidated cookies

Paloaltonetworks · Pan Os

PAN-OS GlobalProtect portal and gateway contain authentication bypass flaws that let an attacker skip security restrictions and establish an unauthorized VPN connection. The weakness is classified as reliance on cookies without validation (CWE-565), meaning a crafted or replayed cookie can be trusted without proper verification. Panorama and Cloud NGFW are not affected.

7.8 CVSS 4.0 High CISA KEV since 29 May 2026 Known ransomware use EPSS 96% · top 0.1% CWE-565 · Reliance on cookies without validation
7.8CVSS 4.0 base score
96%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with known ransomware use, has a near-maximum EPSS score, and allows unauthenticated network attackers to establish a VPN foothold.

What it is

PAN-OS GlobalProtect portal and gateway contain authentication bypass flaws that let an attacker skip security restrictions and establish an unauthorized VPN connection. The weakness is classified as reliance on cookies without validation (CWE-565), meaning a crafted or replayed cookie can be trusted without proper verification. Panorama and Cloud NGFW are not affected.

Impact

An attacker gains an unauthorized VPN session into the protected network, effectively bypassing the authentication boundary. The CVSS 4.0 vector shows low confidentiality impact on the vulnerable system but high subsequent confidentiality and integrity impact, so the real risk is lateral access to internal resources.

Attack surface

Reachable over the network through the GlobalProtect portal and gateway interfaces; the vector indicates no privileges and no user interaction required. No authentication is needed because the flaw itself is the authentication bypass.

Exploitation

Listed in CISA KEV with a due date of 2026-06-01 and flagged for known ransomware campaign use, and EPSS is 0.95156 (99.861st percentile), indicating active exploitation is expected or observed. The vendor and Siemens advisories confirm the issue but do not add exploit detail.

What to do

  • Apply the Palo Alto Networks PAN-OS updates referenced in the vendor advisory security.paloaltonetworks.com/CVE-2026-0257 as the first action.
  • If patching cannot be completed by the CISA due date, apply the vendor's documented mitigations or restrict GlobalProtect portal and gateway exposure per BOD 22-01 guidance.
  • Review Siemens SSA-967325 for any Ruggedcom APE1808 firmware guidance if that product is in scope.
  • Audit GlobalProtect authentication and session logs for unexpected VPN sessions and terminate any that cannot be tied to a legitimate user.
  • Consider disabling or tightly restricting GlobalProtect portal and gateway access from untrusted networks until patched.

Detection

  • Hunt GlobalProtect authentication logs for successful VPN sessions with missing, malformed or replayed cookie attributes, or sessions that do not map to a completed authentication event.
  • Alert on new VPN sessions from unusual geographies, ASNs or IPs that have no prior authentication history.
  • Correlate GlobalProtect session creation with identity provider logs; flag sessions with no matching IdP authentication.
  • Monitor for post-connection lateral movement or internal scanning originating from VPN-assigned addresses.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-0257 to the Known Exploited Vulnerabilities catalog on 29 May 2026 as "Palo Alto Networks PAN-OS Authentication Bypass Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 1 June 2026.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-0257 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-3400PAN-OS GlobalProtect command injection allows unauthenticated root code executionA command injection caused by arbitrary file creation in the GlobalProtect feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker run …KEVEPSS 100%analysed10.0CVE-2020-2021PAN-OS SAML signature verification bypass allows authentication bypassPAN-OS fails to properly verify SAML signatures when SAML authentication is enabled and the 'Validate Identity Provider Certificate' option is unchec…KEVEPSS 4.4%analysed9.8CVE-2026-24858Fortinet FortiCloud SSO authentication bypass across registered devicesA CWE-288 authentication bypass in Fortinet FortiAnalyzer, FortiManager, FortiNAC-F, FortiOS, FortiProxy and FortiWeb lets an attacker with a FortiCl…KEVEPSS 86%analysed9.8CVE-2025-25249Fortinet FortiOS and FortiSwitchManager heap buffer overflow via crafted packetsA heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 through 7.2.6 lets an unauthenticated…KEVEPSS 3.9%analysed9.8CVE-2025-59718Fortinet FortiOS/FortiProxy SAML signature check bypass in FortiCloud SSOFortiOS, FortiProxy and FortiSwitchManager fail to properly verify the cryptographic signature of SAML responses used for FortiCloud SSO login. An un…KEVEPSS 68%analysed9.8CVE-2017-15944PAN-OS management interface input validation flaw allows remote code executionPAN-OS versions before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 contain an input validation and memory buffer overflo…KEVEPSS 98%analysed9.3CVE-2026-0300PAN-OS User-ID Authentication Portal buffer overflow allows root code executionA buffer overflow (out-of-bounds write, CWE-787) in the User-ID Authentication Portal (Captive Portal) service of Palo Alto Networks PAN-OS lets an u…KEVEPSS 32%analysed9.3CVE-2024-0012PAN-OS Management Web Interface Authentication BypassPAN-OS contains a missing authentication flaw (CWE-306) in the management web interface that lets an unauthenticated network attacker obtain PAN-OS a…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2026-0257), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.