CVE-2026-0257

Published May 13, 2026

Last updated a month ago

Exploit knownCVSS high 7.8
PAN-OS
GlobalProtect
Network
SSL
Tunneling protocol
VPN
Server
Firmware

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-0257 is an authentication bypass vulnerability found in the GlobalProtect portal and gateway components of Palo Alto Networks PAN-OS software. This flaw enables an attacker to circumvent security restrictions and establish an unauthorized Virtual Private Network (VPN) connection. The vulnerability stems from the system's reliance on cookies without adequate validation and integrity checking, specifically when authentication override cookies are enabled and a particular certificate configuration is in place. This issue does not impact Panorama or Cloud NGFW deployments.

Description
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.
Source
psirt@paloaltonetworks.com
NVD status
Analyzed
Products
pan-os, prisma_access, ruggedcom_ape1808_firmware

Risk scores

CVSS 4.0

Type
Secondary
Base score
7.8
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:Red
Severity
HIGH

CVSS 3.1

Type
Primary
Base score
9.1
Impact score
5.2
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
Exploit added on
May 29, 2026
Exploit action due
Jun 1, 2026
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

psirt@paloaltonetworks.com
CWE-565

Social media

Hype score
Not currently trending
  1. CVE-2026-0257: 🚨 Palo Alto Warns of GlobalProtect VPN Vulnerability Actively Exploited in the Wild Source: Palo Alto Networks Unit 42 has issued an urgent warning about active exploitation of CVE-2026-0257, a critical authentication bypass…

    @lyrie_ai

    10 Jul 2026

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. palo alto CVE-2026-0257: auth bypass. perimeter appliances are the highest-value target in every breach. patch in maintenance window TODAY. #PaloAltoNetworks #AuthBypass #PANOS #CVE-2026-0257 https://t.co/0gs9DQcS7e

    @trerbbb

    30 Jun 2026

    34 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨June 2026 Recap 🚨New actively exploited vulnerabilities included: 🔹 CVE-2026-0257 (Palo Alto PAN-OS) 🔹 CVE-2026-45247 (Magento RCE) 🔹 CVE-2026-28318 (SolarWinds Serv-U) 🔹 CVE-2026-50751 (Check Point VPN) 🔹 CVE-2026-20245 (Cisco SD-WAN)

    @CoastalCyberSol

    22 Jun 2026

    4 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 2026 is the year of VPN zero-days. Fortinet, Check Point, Ivanti, now Palo Alto CVE-2026-0257 actively exploited. If your entire security posture depends on a VPN appliance at the edge, you are one CVE away from total compromise. #ZeroDay #VPN #Infosec

    @da7rkx0

    20 Jun 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🛡️ CVE-2026-0257: Bypass de Autenticación Crítico en Palo Alto Networks PAN-OS Explotado Activamente Análisis técnico del CVE-2026-0257 en PAN-OS de Palo Alto Networks: bypass de autenticación VPN no autorizado, impacto, productos afectados y mitigaciones. https://t.co/

    @CiberPlanetaOrg

    18 Jun 2026

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🛡️ Alerta de Seguridad: Palo Alto Networks PAN-OS Authentication Bypass en VPN (CVE-2026-0257) Vulnerabilidad crítica en PAN-OS (CWE-565) permite bypass de autenticación y establecimiento de conexiones VPN no autorizadas. Incluida en el catálogo KEV de CISA. Plazo FCEB:

    @CiberPlanetaOrg

    18 Jun 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. ⚠️ Vulnerabilidades en productos Palo Alto ❗ CVE-2026-0265 ❗ CVE-2026-0263 ❗ CVE-2026-0257 ➡️ Más info: https://t.co/I8y6zYFcGw https://t.co/pRL81cMl80

    @CERTpy

    16 Jun 2026

    71 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Palo Alto Networksは、PAN-OSの脆弱性におけるVPNバイパス攻撃(CVE-2026-0257)の悪用について警告を発しました Palo Alto Warns of Exploitation of VPN Bypass Exploits (CVE-2026-0257) in PAN-OS Flaw #SecurityAffairs (Jun 15) https://t.co/3z4nIpE1Kz

    @foxbook

    16 Jun 2026

    249 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  9. Palo Alto Warns of Exploitation of VPN Bypass Exploits (CVE-2026-0257) in PAN-OS Flaw: Palo Alto Networks warns that attackers are actively exploiting CVE-2026-0257, a PAN-OS flaw that lets unauthorized users bypass authentication and establish VPN… https://t.co/wmUE1jI8QF

    @shah_sheikh

    15 Jun 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Arctic Wolf Observes an Increase in Palo Alto Networks GlobalProtect Authentication Bypass Exploitation via CVE-2026-0257 https://t.co/WI9aMSG43v Key Takeaways Arctic Wolf observed a wave of CVE-2026-0257 exploitation activity in late May and early June 2026, following the pub

    @f1tym1

    11 Jun 2026

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Threat Intel Brief — 2026-06-11 SUMMARY Today’s top signal is exposed PAN-OS / GlobalProtect infrastructure. Unit 42 reports active exploitation of CVE-2026-0257. CISA has it in KEV. FIRST EPSS puts it in the 98th percentile. No public lateral movement yet. That is not

    @alphahunt_io

    11 Jun 2026

    186 Impressions

    1 Retweet

    4 Likes

    0 Bookmarks

    2 Replies

    0 Quotes

  12. # Palo Alto PAN-OS GlobalProtect CVE-2026-0257 Military-Grade Exploit Kit **LEGENDARY Authentication Override Cookie Forgery Framework for VPN Hijacking and Internal Network Access.** CVE-2026-0257 **Real exploitation**: - ✅ Public key extraction from HTTPS cert - ✅ Admin

    @YogSoth0

    10 Jun 2026

    79 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. 00:00 UTC: CVE-2026-0257 disclosed. CISA: CVE-2026-0257 added to Known Exploited Vulnerabilities — Palo Alto Networks PAN-OS Status: ✅ Confirmed exploited in the wild Date added: 2026-05-29 Required action: Apply mitigations per vendor instructions, follow applicable…

    @lyrie_ai

    10 Jun 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  14. CVE-2026-0257: Palo Alto GlobalProtect (CVE-2026-0257, CVSS 9.8) is actively exploited. Auth override cookies use a cert; when shared with the HTTPS portal, attackers extract the public key and forge valid cookies. Fixed: PAN-OS 11.2.12, 12.1.7. CISA patches due June 19.…

    @lyrie_ai

    8 Jun 2026

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  15. CVE-2026-0257: 🚨 Palo Alto Networks PAN-OS Authentication Vulnerability Bypass Exploited in the Wild Source: Palo Alto Networks authentication bypass vulnerability, CVE-2026-0257, affecting PAN-OS and Prisma Access, is now being actively exploited…

    @lyrie_ai

    8 Jun 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  16. New zero-day in Cisco SD-WAN (CVE-2026-20245) actively exploited, no patch available. Palo Alto PAN-OS (CVE-2026-0257) also targeted for auth bypass. Critical risk to data privacy & integrity in transit. #Cybersecurity #News #Vulnerabilities

    @YourAnon_irc

    7 Jun 2026

    85 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. ⚠️ Active Exploitation Alert! Unidentified actors are exploiting PAN-OS auth bypass CVE-2026-0257 to access GlobalProtect VPNs. CISA KEV listed. Patch or apply mitigations immediately to prevent unauthorized access. #PANOS #CVE #CyberSecurity 🌐 cyber[.]netsecops[.]io http

    @NetSecIO

    6 Jun 2026

    72 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. CVE-2026-0257: Rapid7 Caught Attackers Abusing Forged VPN Cookies Against Multiple Customers https://t.co/Wnumz9Rh3R

    @samilaiho

    6 Jun 2026

    370 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 https://t.co/gxGO6gzpVo

    @samilaiho

    6 Jun 2026

    156 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. استغلال نشط لثغرة PAN-OS CVE-2026-0257 استغلال نشط لثغرة PAN-OS CVE-2026-0257، مع مؤشرات هجوم وتخفيفات من Unit 42. #PAN_OS #CVE_2026_0257 https://t.co/zLkVaiteEe

    @sultan_alhajlah

    5 Jun 2026

    46 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  21. Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 https://t.co/Q6yhIYGKUY

    @pigram86

    5 Jun 2026

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. Top 5 Trending CVEs: 1 - CVE-2025-53773 2 - CVE-2025-32711 3 - CVE-2022-0492 4 - CVE-2024-21182 5 - CVE-2026-0257 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    3 Jun 2026

    101 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  23. Recent zero-day & critical CVEs demand attention! PAN-OS auth bypass (CVE-2026-0257) exploited, risking VPN integrity. Android zero-day (CVE-2025-48595) patched. QUIC protocol flaws (wolfSSL, HAProxy, Nginx) threaten secure data in transit. #Cybersecurity #Vulnerabilities #Ne

    @YourAnon_irc

    2 Jun 2026

    83 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. A critical CVE doesn't mean every box is on fire. CVE-2026-0257 (Palo Alto GlobalProtect, 9.1, actively exploited) only bites if two things are true: authentication override is enabled AND its cookie certificate is reused elsewhere. The config detail a CVE ID never tells you:

    @vuln_tracker

    2 Jun 2026

    39 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  25. Top 5 Trending CVEs: 1 - CVE-2024-21182 2 - CVE-2026-40369 3 - CVE-2026-0257 4 - CVE-2023-41011 5 - CVE-2026-35563 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    2 Jun 2026

    161 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. Sale of a 1‑day exploit for vulnerability CVE-2026-0257 -> (https://t.co/rBfUMze8Em) PT ID: PT-2026-40754 For informational purposes only. CVE-2026-0257 -> (https://t.co/rBfUMze8Em) is an authentication bypass vulnerability in the GlobalProtect portal and gateway of Pa

    @ptdbugs

    2 Jun 2026

    156 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. ハッカーがPalo Alto GlobalProtect VPNの認証バイパス脆弱性(CVE-2026-0257)を悪用しています Hackers are exploiting Palo Alto GlobalProtect VPN authentication bypass (CVE-2026-0257) #HelpNetSecurity (Jun 1) https://t.co/lGv3RSYEvg

    @foxbook

    2 Jun 2026

    313 Impressions

    0 Retweets

    1 Like

    2 Bookmarks

    0 Replies

    0 Quotes

  28. Palo Alto Networks CVE-2026-0257, an auth-bypass flaw, was rapidly escalated to critical after active exploitation. Attackers can bypass controls and gain VPN access. CISA added it to KEV. #CVE-2026-0257 #PaloAltoNetworks #CISA https://t.co/1PVRn6YXiw

    @TweetThreatNews

    2 Jun 2026

    156 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  29. 現役で使われているVPN・ドメインコントローラ・ホテル端末。今日はその「みんな知ってる名前」が同時に殴られた日だ。 ・PAN-OS GlobalProtect認証バイパス、CVE-2026-0257がKEV入り ・Windows Netlogon RCE、CVE-2026-41089が

    @boss_sec_labo

    1 Jun 2026

    677 Impressions

    1 Retweet

    5 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  30. ثغرة تجاوز مصادقة حرجة في GlobalProtect تُستغل فعلياً، وأضافتها CISA لقائمة KEV المعرّف : CVE-2026-0257 درجة الخطورة : 9.1 (CVSS) - Critical المنتجات المتأثرة : PAN-OS, Prisma Access الحل :

    @KasperskyDev

    1 Jun 2026

    83 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  31. Hackers are exploiting Palo Alto GlobalProtect VPN authentication bypass (CVE-2026-0257) https://t.co/BV5KzNSG7Y

    @TheCyberSecHub

    1 Jun 2026

    376 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. 🚨 CVE-2026-0257: PAN-OS GlobalProtect authentication bypass is under active exploitation. Attackers may establish unauthorized VPN connections and access internal network resources. https://t.co/ULaT3KuFhY #PANOS #GlobalProtect #PaloAltoNetworks #CVE #VPNSecurity #Vulert

    @vulert_official

    1 Jun 2026

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. Hackers are exploiting Palo Alto GlobalProtect VPN authentication bypass (CVE-2026-0257): Authentication bypass vulnerabilities (CVE-2026-0257) in Palo Alto Networks’ firewalls that the company disclosed on May 13 have been targeted in “limited exploit… https://t.co/xBJVYgc

    @shah_sheikh

    1 Jun 2026

    58 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. ثغرة تُستغل فعلياً عبر ملفات تعريف VPN مزوّرة. رصدت Rapid7 استغلال CVE 2026 0257 ضد عدة عملاء، ما يبرز أهمية مراقبة سلامة جلسات VPN وليس تسجيل الدخول فقط. Forged VPN cookies ar

    @fad_777

    1 Jun 2026

    100 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  35. Top 5 Trending CVEs: 1 - CVE-2026-45585 2 - CVE-2025-36911 3 - CVE-2026-31525 4 - CVE-2026-0257 5 - CVE-2026-28910 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    1 Jun 2026

    104 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  36. PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities CVE: CVE-2026-0257 PT ID: PT-2026-40754 Vendor: Palo Alto Networks Product: Cloud NGFW CVSS: 7.8 Credits: Internal security research (Palo Alto Networks) Description: Authentication bypass vulnerabilities in the

    @ptdbugs

    1 Jun 2026

    123 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  37. CVE-2026-0257: Rapid7は、複数の顧客に対して偽造VPNクッキーを悪用する攻撃者を発見した CVE-2026-0257: Rapid7 Caught Attackers Abusing Forged VPN Cookies Against Multiple Customers #SecurityAffairs (May 31) https://t.co/qqiLsofZWR

    @foxbook

    1 Jun 2026

    339 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. PAN-OS GlobalProtect認証バイパス(CVE-2026-0257)が現在悪用されています PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation #HackerNews (May 30) https://t.co/U9V9t35Xym

    @foxbook

    1 Jun 2026

    321 Impressions

    0 Retweets

    1 Like

    2 Bookmarks

    0 Replies

    0 Quotes

  39. 【PAN-OS GlobalProtect認証回避CVE-2026-0257が実悪用】 Palo Alto NetworksのPAN-OS/Prisma Accessに影響するCVE-2026-0257が、GlobalProtect環境で実悪用されています。 この脆弱性は、条件を満たす構成でauthentication override

    @01ra66it

    31 May 2026

    390 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  40. PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation https://t.co/wns1RkestG

    @TechNowPulse

    31 May 2026

    51 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  41. #threatreport #LowCompleteness Rapid7 Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257) | 29-05-2026 Source: https://t.co/KmN4mLeaH6 Key details below ↓ 🎯Victims: Organizations using pan os, Organizations using prisma access,

    @rst_cloud

    31 May 2026

    130 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  42. CVE-2026-0257: Rapid7 Caught Attackers Abusing Forged VPN Cookies Against Multiple ... https://t.co/8V9tLHXwC9 #forgery #forensic-document-examiner

    @ForensicDocExam

    31 May 2026

    68 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. CVE-2026-0257: Rapid7 Caught Attackers Abusing Forged VPN Cookies Against Multiple Customers https://t.co/RBTbGZZQ4Z

    @VivekIntel

    31 May 2026

    2308 Impressions

    5 Retweets

    27 Likes

    7 Bookmarks

    0 Replies

    0 Quotes

  44. CVE-2026-0257: Rapid7 Caught Attackers Abusing Forged VPN Cookies Against Multiple Customers https://t.co/ggk6tM7wrO #securityaffairs #hacking #PaloAltoNetworks @rapid7

    @securityaffairs

    31 May 2026

    491 Impressions

    4 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  45. PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation https://t.co/gZZve26mXo via @TheHackersNews

    @BernierStrategy

    31 May 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  46. PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation https://t.co/G7kv2tydMC

    @samilaiho

    31 May 2026

    426 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  47. 【サイバーセキュリティ動向分析】 現在のトレンドセキュリティニュース(2026年5月31日時点) PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) が積極的に悪用中 https://t.co/hmqRlLQJDl ChatGPhish Vulnerability:ChatGPTのWeb

    @kenebeii

    31 May 2026

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  48. Palo Alto GlobalProtect VPN flaw (CVE-2026-0257) now actively exploited! Hackers are breaching corporate networks via auth bypass. Patch up, people! Source: BleepingComputer. #CyberAttack #VPN https://t.co/0bwfKiKEWf

    @computerauditor

    31 May 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  49. Noticias clave de ciberseguridad 🚨: GlobalProtect VPN (CVE-2026-0257) explotada activamente, y falla ‘CIFSwitch’ en Linux permite escalada a root. ¡Actualiza tus sistemas ya! https://t.co/1hcA73bCj0

    @MiAnCa_dev

    31 May 2026

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  50. Top 5 Trending CVEs: 1 - CVE-2026-48095 2 - CVE-2026-45585 3 - CVE-2026-40369 4 - CVE-2026-42826 5 - CVE-2026-0257 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    31 May 2026

    148 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations