CVE-2026-0257

Published May 13, 2026

Last updated 4 days ago

Exploit knownCVSS high 7.8
PAN-OS
GlobalProtect
Network
SSL
Tunneling protocol
Firmware

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-0257 is an authentication bypass vulnerability found in the GlobalProtect portal and gateway components of Palo Alto Networks PAN-OS software. This flaw enables an attacker to circumvent security restrictions and establish an unauthorized Virtual Private Network (VPN) connection. The vulnerability stems from the system's reliance on cookies without adequate validation and integrity checking, specifically when authentication override cookies are enabled and a particular certificate configuration is in place. This issue does not impact Panorama or Cloud NGFW deployments.

Description
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.
Source
psirt@paloaltonetworks.com
NVD status
Analyzed
Products
pan-os, prisma_access, ruggedcom_ape1808_firmware

Risk scores

CVSS 4.0

Type
Secondary
Base score
7.8
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:Red
Severity
HIGH

CVSS 3.1

Type
Primary
Base score
9.1
Impact score
5.2
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
Exploit added on
May 29, 2026
Exploit action due
Jun 1, 2026
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

psirt@paloaltonetworks.com
CWE-565

Social media

Hype score
Not currently trending
  1. Arctic Wolf Observes an Increase in Palo Alto Networks GlobalProtect Authentication Bypass Exploitation via CVE-2026-0257 https://t.co/WI9aMSG43v Key Takeaways Arctic Wolf observed a wave of CVE-2026-0257 exploitation activity in late May and early June 2026, following the pub

    @f1tym1

    11 Jun 2026

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Threat Intel Brief — 2026-06-11 SUMMARY Today’s top signal is exposed PAN-OS / GlobalProtect infrastructure. Unit 42 reports active exploitation of CVE-2026-0257. CISA has it in KEV. FIRST EPSS puts it in the 98th percentile. No public lateral movement yet. That is not

    @alphahunt_io

    11 Jun 2026

    186 Impressions

    1 Retweet

    4 Likes

    0 Bookmarks

    2 Replies

    0 Quotes

  3. # Palo Alto PAN-OS GlobalProtect CVE-2026-0257 Military-Grade Exploit Kit **LEGENDARY Authentication Override Cookie Forgery Framework for VPN Hijacking and Internal Network Access.** CVE-2026-0257 **Real exploitation**: - ✅ Public key extraction from HTTPS cert - ✅ Admin

    @YogSoth0

    10 Jun 2026

    79 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 00:00 UTC: CVE-2026-0257 disclosed. CISA: CVE-2026-0257 added to Known Exploited Vulnerabilities — Palo Alto Networks PAN-OS Status: ✅ Confirmed exploited in the wild Date added: 2026-05-29 Required action: Apply mitigations per vendor instructions, follow applicable…

    @lyrie_ai

    10 Jun 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. CVE-2026-0257: Palo Alto GlobalProtect (CVE-2026-0257, CVSS 9.8) is actively exploited. Auth override cookies use a cert; when shared with the HTTPS portal, attackers extract the public key and forge valid cookies. Fixed: PAN-OS 11.2.12, 12.1.7. CISA patches due June 19.…

    @lyrie_ai

    8 Jun 2026

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. CVE-2026-0257: 🚨 Palo Alto Networks PAN-OS Authentication Vulnerability Bypass Exploited in the Wild Source: Palo Alto Networks authentication bypass vulnerability, CVE-2026-0257, affecting PAN-OS and Prisma Access, is now being actively exploited…

    @lyrie_ai

    8 Jun 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  7. New zero-day in Cisco SD-WAN (CVE-2026-20245) actively exploited, no patch available. Palo Alto PAN-OS (CVE-2026-0257) also targeted for auth bypass. Critical risk to data privacy & integrity in transit. #Cybersecurity #News #Vulnerabilities

    @YourAnon_irc

    7 Jun 2026

    85 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. ⚠️ Active Exploitation Alert! Unidentified actors are exploiting PAN-OS auth bypass CVE-2026-0257 to access GlobalProtect VPNs. CISA KEV listed. Patch or apply mitigations immediately to prevent unauthorized access. #PANOS #CVE #CyberSecurity 🌐 cyber[.]netsecops[.]io http

    @NetSecIO

    6 Jun 2026

    72 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CVE-2026-0257: Rapid7 Caught Attackers Abusing Forged VPN Cookies Against Multiple Customers https://t.co/Wnumz9Rh3R

    @samilaiho

    6 Jun 2026

    370 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 https://t.co/gxGO6gzpVo

    @samilaiho

    6 Jun 2026

    156 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. استغلال نشط لثغرة PAN-OS CVE-2026-0257 استغلال نشط لثغرة PAN-OS CVE-2026-0257، مع مؤشرات هجوم وتخفيفات من Unit 42. #PAN_OS #CVE_2026_0257 https://t.co/zLkVaiteEe

    @sultan_alhajlah

    5 Jun 2026

    46 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 https://t.co/Q6yhIYGKUY

    @pigram86

    5 Jun 2026

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Top 5 Trending CVEs: 1 - CVE-2025-53773 2 - CVE-2025-32711 3 - CVE-2022-0492 4 - CVE-2024-21182 5 - CVE-2026-0257 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    3 Jun 2026

    101 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Recent zero-day & critical CVEs demand attention! PAN-OS auth bypass (CVE-2026-0257) exploited, risking VPN integrity. Android zero-day (CVE-2025-48595) patched. QUIC protocol flaws (wolfSSL, HAProxy, Nginx) threaten secure data in transit. #Cybersecurity #Vulnerabilities #Ne

    @YourAnon_irc

    2 Jun 2026

    83 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. A critical CVE doesn't mean every box is on fire. CVE-2026-0257 (Palo Alto GlobalProtect, 9.1, actively exploited) only bites if two things are true: authentication override is enabled AND its cookie certificate is reused elsewhere. The config detail a CVE ID never tells you:

    @vuln_tracker

    2 Jun 2026

    39 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  16. Top 5 Trending CVEs: 1 - CVE-2024-21182 2 - CVE-2026-40369 3 - CVE-2026-0257 4 - CVE-2023-41011 5 - CVE-2026-35563 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    2 Jun 2026

    161 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. Sale of a 1‑day exploit for vulnerability CVE-2026-0257 -> (https://t.co/rBfUMze8Em) PT ID: PT-2026-40754 For informational purposes only. CVE-2026-0257 -> (https://t.co/rBfUMze8Em) is an authentication bypass vulnerability in the GlobalProtect portal and gateway of Pa

    @ptdbugs

    2 Jun 2026

    156 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. ハッカーがPalo Alto GlobalProtect VPNの認証バイパス脆弱性(CVE-2026-0257)を悪用しています Hackers are exploiting Palo Alto GlobalProtect VPN authentication bypass (CVE-2026-0257) #HelpNetSecurity (Jun 1) https://t.co/lGv3RSYEvg

    @foxbook

    2 Jun 2026

    313 Impressions

    0 Retweets

    1 Like

    2 Bookmarks

    0 Replies

    0 Quotes

  19. Palo Alto Networks CVE-2026-0257, an auth-bypass flaw, was rapidly escalated to critical after active exploitation. Attackers can bypass controls and gain VPN access. CISA added it to KEV. #CVE-2026-0257 #PaloAltoNetworks #CISA https://t.co/1PVRn6YXiw

    @TweetThreatNews

    2 Jun 2026

    156 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  20. 現役で使われているVPN・ドメインコントローラ・ホテル端末。今日はその「みんな知ってる名前」が同時に殴られた日だ。 ・PAN-OS GlobalProtect認証バイパス、CVE-2026-0257がKEV入り ・Windows Netlogon RCE、CVE-2026-41089が

    @boss_sec_labo

    1 Jun 2026

    677 Impressions

    1 Retweet

    5 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  21. ثغرة تجاوز مصادقة حرجة في GlobalProtect تُستغل فعلياً، وأضافتها CISA لقائمة KEV المعرّف : CVE-2026-0257 درجة الخطورة : 9.1 (CVSS) - Critical المنتجات المتأثرة : PAN-OS, Prisma Access الحل :

    @KasperskyDev

    1 Jun 2026

    83 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  22. Hackers are exploiting Palo Alto GlobalProtect VPN authentication bypass (CVE-2026-0257) https://t.co/BV5KzNSG7Y

    @TheCyberSecHub

    1 Jun 2026

    376 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. 🚨 CVE-2026-0257: PAN-OS GlobalProtect authentication bypass is under active exploitation. Attackers may establish unauthorized VPN connections and access internal network resources. https://t.co/ULaT3KuFhY #PANOS #GlobalProtect #PaloAltoNetworks #CVE #VPNSecurity #Vulert

    @vulert_official

    1 Jun 2026

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. Hackers are exploiting Palo Alto GlobalProtect VPN authentication bypass (CVE-2026-0257): Authentication bypass vulnerabilities (CVE-2026-0257) in Palo Alto Networks’ firewalls that the company disclosed on May 13 have been targeted in “limited exploit… https://t.co/xBJVYgc

    @shah_sheikh

    1 Jun 2026

    58 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. ثغرة تُستغل فعلياً عبر ملفات تعريف VPN مزوّرة. رصدت Rapid7 استغلال CVE 2026 0257 ضد عدة عملاء، ما يبرز أهمية مراقبة سلامة جلسات VPN وليس تسجيل الدخول فقط. Forged VPN cookies ar

    @fad_777

    1 Jun 2026

    100 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  26. Top 5 Trending CVEs: 1 - CVE-2026-45585 2 - CVE-2025-36911 3 - CVE-2026-31525 4 - CVE-2026-0257 5 - CVE-2026-28910 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    1 Jun 2026

    104 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  27. PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities CVE: CVE-2026-0257 PT ID: PT-2026-40754 Vendor: Palo Alto Networks Product: Cloud NGFW CVSS: 7.8 Credits: Internal security research (Palo Alto Networks) Description: Authentication bypass vulnerabilities in the

    @ptdbugs

    1 Jun 2026

    123 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  28. CVE-2026-0257: Rapid7は、複数の顧客に対して偽造VPNクッキーを悪用する攻撃者を発見した CVE-2026-0257: Rapid7 Caught Attackers Abusing Forged VPN Cookies Against Multiple Customers #SecurityAffairs (May 31) https://t.co/qqiLsofZWR

    @foxbook

    1 Jun 2026

    339 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. PAN-OS GlobalProtect認証バイパス(CVE-2026-0257)が現在悪用されています PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation #HackerNews (May 30) https://t.co/U9V9t35Xym

    @foxbook

    1 Jun 2026

    321 Impressions

    0 Retweets

    1 Like

    2 Bookmarks

    0 Replies

    0 Quotes

  30. 【PAN-OS GlobalProtect認証回避CVE-2026-0257が実悪用】 Palo Alto NetworksのPAN-OS/Prisma Accessに影響するCVE-2026-0257が、GlobalProtect環境で実悪用されています。 この脆弱性は、条件を満たす構成でauthentication override

    @01ra66it

    31 May 2026

    390 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  31. PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation https://t.co/wns1RkestG

    @TechNowPulse

    31 May 2026

    51 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. #threatreport #LowCompleteness Rapid7 Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257) | 29-05-2026 Source: https://t.co/KmN4mLeaH6 Key details below ↓ 🎯Victims: Organizations using pan os, Organizations using prisma access,

    @rst_cloud

    31 May 2026

    130 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. CVE-2026-0257: Rapid7 Caught Attackers Abusing Forged VPN Cookies Against Multiple ... https://t.co/8V9tLHXwC9 #forgery #forensic-document-examiner

    @ForensicDocExam

    31 May 2026

    68 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. CVE-2026-0257: Rapid7 Caught Attackers Abusing Forged VPN Cookies Against Multiple Customers https://t.co/RBTbGZZQ4Z

    @VivekIntel

    31 May 2026

    2308 Impressions

    5 Retweets

    27 Likes

    7 Bookmarks

    0 Replies

    0 Quotes

  35. CVE-2026-0257: Rapid7 Caught Attackers Abusing Forged VPN Cookies Against Multiple Customers https://t.co/ggk6tM7wrO #securityaffairs #hacking #PaloAltoNetworks @rapid7

    @securityaffairs

    31 May 2026

    491 Impressions

    4 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  36. PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation https://t.co/gZZve26mXo via @TheHackersNews

    @BernierStrategy

    31 May 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation https://t.co/G7kv2tydMC

    @samilaiho

    31 May 2026

    426 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  38. 【サイバーセキュリティ動向分析】 現在のトレンドセキュリティニュース(2026年5月31日時点) PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) が積極的に悪用中 https://t.co/hmqRlLQJDl ChatGPhish Vulnerability:ChatGPTのWeb

    @kenebeii

    31 May 2026

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. Palo Alto GlobalProtect VPN flaw (CVE-2026-0257) now actively exploited! Hackers are breaching corporate networks via auth bypass. Patch up, people! Source: BleepingComputer. #CyberAttack #VPN https://t.co/0bwfKiKEWf

    @computerauditor

    31 May 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  40. Noticias clave de ciberseguridad 🚨: GlobalProtect VPN (CVE-2026-0257) explotada activamente, y falla ‘CIFSwitch’ en Linux permite escalada a root. ¡Actualiza tus sistemas ya! https://t.co/1hcA73bCj0

    @MiAnCa_dev

    31 May 2026

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  41. Top 5 Trending CVEs: 1 - CVE-2026-48095 2 - CVE-2026-45585 3 - CVE-2026-40369 4 - CVE-2026-42826 5 - CVE-2026-0257 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    31 May 2026

    148 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  42. تم رصد استغلال ثغرة تجاوز المصادقة في PAN-OS GlobalProtect (CVE-2026-0257) من قبل Rapid7. Rapid7 has detected the exploitation of the PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257) https://t.co/YnGLFROgKz #Rapid7 #PA

    @fad_777

    31 May 2026

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. Alerte #CyberSecurity 🚨 : Une faille d’authentification dans PAN-OS #GlobalProtect (CVE-2026-0257, score 7.8) est activement exploitée, permettant de contourner la sécurité VPN. https://t.co/makc55BrCH

    @meg_ai_fr

    31 May 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  44. The Cookie Forger: How a Cryptographic Shortcut Opened Palo Alto VPNs That single log line was the first confirmed signal of active exploitation of CVE-2026-0257, a bypass vulnerability in PAN-OS that PaloAlto had disclosed just five days earlier. https://t.co/t8J7E8ChDO

    @EnigmaGlobalSW

    31 May 2026

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  45. 先に話題になってたCVE-2026-0265よりまCVE-2026-0257の方が構成条件的に脆弱な機器が多いと思うので心配。

    @poppo9494

    31 May 2026

    70 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  46. Rapid7 observed active exploitation of CVE-2026-0257 in PAN-OS and Prisma Access, where forged GlobalProtect override cookies bypassed login on vulnerable systems. #PaloAlto #GlobalProtect #CVE2026-0257 https://t.co/MxCLdjysm7

    @TweetThreatNews

    31 May 2026

    175 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  47. CVE-2026-0257、PAN-OS GlobalProtectで認証バイパス。 攻撃者が管理画面に不正アクセス可能。 ↓詳細はリプライで #脆弱性 https://t.co/vJ1qNcVBK3

    @motch_dev

    31 May 2026

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  48. PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation https://t.co/anzyewqXt3

    @JedisecX

    31 May 2026

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  49. Palo Alto PAN-OS Authentication Bypass Vulnerability Actively Exploited in the Wild https://t.co/cVJlBcLi9p "In response to mounting attacks, the CISA added CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) catalog on May 29, 2026."

    @catnap707

    31 May 2026

    159 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  50. PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation https://t.co/M7mM7ZhCGZ

    @Tech_Newsletter

    31 May 2026

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations