/Vulnerability Library

Palo Alto Networks PAN-OS - Authentication Bypass

CVE-2026-0257
Verified

Description

Palo Alto Networks PAN-OS contains an authentication bypass caused by flaws in the GlobalProtect portal and gateway, letting attackers establish unauthorized VPN connections, exploit requires network access to the portal or gateway.

Severity

Critical

CVSS Score

9.1

Exploit Probability

96%

Affected Product

pan-os

Published Date

June 1, 2026

Template Author

dhiyaneshdk, sfewer-r7

CVE-2026-0257.yaml
9.1Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVE ID:
cve-2026-0257
CWE ID:
cwe-565

References

https://security.paloaltonetworks.com/CVE-2026-0257https://www.rapid7.com/blog/post/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257/https://github.com/sfewer-r7/CVE-2026-0257

Remediation Steps

Update to the latest PAN-OS version that addresses GlobalProtect authentication bypass.