CVE-2026-0257
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
Description
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.
In plain language
AI Act nowCVE-2026-0257 is a serious GlobalProtect login-bypass flaw in PAN-OS that lets attackers connect a fake VPN session without authenticating; if you run PAN-OS GlobalProtect (portal or gateway), you should treat this as urgent and patch immediately.
CVE-2026-0257 is a GlobalProtect authentication bypass in PAN-OS (GlobalProtect portal and gateway) that allows an attacker to bypass authentication and establish an unauthorized VPN connection over the network; CISA added it to KEV with active exploitation reported.
What to do now
- Check whether your firewalls have PAN-OS installed and whether GlobalProtect “portal” and/or “gateway” are enabled.
- Identify your exact PAN-OS version (and whether you use GlobalProtect authentication override cookies).
- Upgrade PAN-OS to a fixed release: 12.1.7, 12.1.4-h6, 11.2.12, 11.2.10-h7, 11.2.7-h14, 11.2.4-h17, 11.1.15, 11.1.13-h5, 11.1.10-h25, 11.1.7-h6, 11.1.6-h32, 11.1.4-h33, or 10.2.18-h6 (and the other fixed versions listed for your branch).
- For Prisma Access, upgrade to 10.2.10-h36 or 11.2.7-h13.
- If you cannot patch right away, follow Palo Alto Networks’ vendor mitigations/workarounds from the vendor advisory and disable or restrict any exposed GlobalProtect interfaces as directed.
- Validate after changes that GlobalProtect portal/gateway authentication behavior is back to normal and plan for re-authentication if you use authentication override cookies.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
- Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Accessen·The Hacker News· Exploited PAN-OS Qilin Ransomware Group
- Critical Palo Alto VPN bug now exploited by Qilin ransomware gangen-us·BleepingComputer· Exploited GlobalProtect Qilin
- Малварь ChocoPoC распространяется под видом фальшивых эксплоитовru-ru·Хакер (xakep.ru)· PoC malware
- В фокусе RVD: трендовые уязвимости июняru·Хабр — Информационная безопасность· Roundup linux kernel
- New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Reposen·The Hacker News· PoC malware
- ChocoPoc malware delivered via trojanized exploits on GitHuben-us·BleepingComputer· PoC ChocoPoC malware
- New ChocoPoC malware targets researchers via trojanized PoC exploitsen-us·BleepingComputer· PoC ChocoPoC malware
- Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flawen·The Hacker News· Exploited PAN-OS GlobalProtect (portal and gateway) auth-bypass
- Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257en-us·Palo Alto Unit 42· Exploited PAN-OS auth-bypass
- 1st June – Threat Intelligence Reporten-us·Check Point Research· Roundup ShinyHunters data-breach
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-0257 and every CVE in our database. Create a free account — no credit card required.
Create Free Account