Vulnerability record · CVE-2026-0257 · published 13 May 2026
CVE-2026-0257: PAN-OS GlobalProtect authentication bypass via unvalidated cookies
Paloaltonetworks · Pan Os
PAN-OS GlobalProtect portal and gateway contain authentication bypass flaws that let an attacker skip security restrictions and establish an unauthorized VPN connection. The weakness is classified as reliance on cookies without validation (CWE-565), meaning a crafted or replayed cookie can be trusted without proper verification. Panorama and Cloud NGFW are not affected.
Description
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:
Automated analysis
critical priorityIt is in CISA KEV with known ransomware use, has a near-maximum EPSS score, and allows unauthenticated network attackers to establish a VPN foothold.
What it is
PAN-OS GlobalProtect portal and gateway contain authentication bypass flaws that let an attacker skip security restrictions and establish an unauthorized VPN connection. The weakness is classified as reliance on cookies without validation (CWE-565), meaning a crafted or replayed cookie can be trusted without proper verification. Panorama and Cloud NGFW are not affected.
Impact
An attacker gains an unauthorized VPN session into the protected network, effectively bypassing the authentication boundary. The CVSS 4.0 vector shows low confidentiality impact on the vulnerable system but high subsequent confidentiality and integrity impact, so the real risk is lateral access to internal resources.
Attack surface
Reachable over the network through the GlobalProtect portal and gateway interfaces; the vector indicates no privileges and no user interaction required. No authentication is needed because the flaw itself is the authentication bypass.
Exploitation
Listed in CISA KEV with a due date of 2026-06-01 and flagged for known ransomware campaign use, and EPSS is 0.95156 (99.861st percentile), indicating active exploitation is expected or observed. The vendor and Siemens advisories confirm the issue but do not add exploit detail.
What to do
- Apply the Palo Alto Networks PAN-OS updates referenced in the vendor advisory security.paloaltonetworks.com/CVE-2026-0257 as the first action.
- If patching cannot be completed by the CISA due date, apply the vendor's documented mitigations or restrict GlobalProtect portal and gateway exposure per BOD 22-01 guidance.
- Review Siemens SSA-967325 for any Ruggedcom APE1808 firmware guidance if that product is in scope.
- Audit GlobalProtect authentication and session logs for unexpected VPN sessions and terminate any that cannot be tied to a legitimate user.
- Consider disabling or tightly restricting GlobalProtect portal and gateway access from untrusted networks until patched.
Detection
- Hunt GlobalProtect authentication logs for successful VPN sessions with missing, malformed or replayed cookie attributes, or sessions that do not map to a completed authentication event.
- Alert on new VPN sessions from unusual geographies, ASNs or IPs that have no prior authentication history.
- Correlate GlobalProtect session creation with identity provider logs; flag sessions with no matching IdP authentication.
- Monitor for post-connection lateral movement or internal scanning originating from VPN-assigned addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-0257 to the Known Exploited Vulnerabilities catalog on 29 May 2026 as "Palo Alto Networks PAN-OS Authentication Bypass Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 1 June 2026.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://security.paloaltonetworks.com/CVE-2026-0257 | Vendor Advisory |
| https://cert-portal.siemens.com/productcert/html/ssa-967325.html | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-0257 | US Government Resource |
Track CVE-2026-0257 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-0257), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.