CVE-2026-0265
PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled
Description
Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Siemens is preparing fix versions and recommends countermeasures for products where fixes are not, or not yet available. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications. [1] https://security.paloaltonetworks.com/
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- What’s New in Rapid7 Products and Services: Q2 2026 in Reviewen·Rapid7 Blog· Research
- Detecting CVE-2026-0265 at Scale: PAN-OS CAS Authentication Bypassen-us·Bishop Fox· Patch PAN-OS auth-bypass
- CVE-2026-0265: Authentication Bypass in Palo Alto Networks PAN-OSen·Rapid7 Blog· Advisory PAN-OS HacktronAI
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-0265 and every CVE in our database. Create a free account — no credit card required.
Create Free Account