PAN-OS GlobalProtect auth bypass (CVE-2026-0257) [PoC]
CVE-2026-0257
CVE-2026-0257: Palo Alto PAN-OS GlobalProtect authentication bypass crushes VPN security restrictions. Actively exploited in the wild. Update to patched PAN-OS versions.
Actively exploited in the wild - CVE-2026-0257 is a critical authentication bypass in Palo Alto Networks PAN-OS GlobalProtect portal and gateway that lets unauthenticated attackers establish unauthorized VPN connections. CISA has confirmed active exploitation; apply vendor patches immediately.
Overview
CVE-2026-0257 is a critical vulnerability in Palo Alto Networks PAN-OS software affecting the GlobalProtect portal and gateway components. The flaw allows an unauthenticated attacker to bypass security restrictions and establish a VPN connection without proper credentials. This means an attacker on the network can gain unauthorized access to the protected internal network as if they were a legitimate VPN user.
The vulnerability carries a CVSS score of 9.1 (Critical) with a network attack vector, low attack complexity, and no privileges or user interaction required. Panorama and Cloud NGFW are not impacted.
Impact
Successful exploitation of CVE-2026-0257 enables an attacker to:
- Bypass GlobalProtect authentication mechanisms
- Establish unauthorized VPN tunnels into the protected network
- Gain access to internal resources that would normally be restricted to authenticated VPN users
- Launch further attacks against internal systems from an authenticated VPN session
The low EPSS score (0.1%) suggests exploitation remains targeted rather than widespread automated scanning. However, CISA’s inclusion on the Known Exploited Vulnerabilities catalog indicates active, confirmed in-the-wild attacks.
Affected Products and Remediation
Palo Alto Networks has released security updates for this vulnerability. Specific patched versions vary by PAN-OS release train. Organizations should:
- Update PAN-OS to the latest patched version immediately for affected GlobalProtect deployments
- Review vendor advisory for exact version numbers
- Monitor GlobalProtect logs for unauthorized VPN connections
- Implement network segmentation to limit lateral movement for any potentially compromised sessions
Apply patches to all PAN-OS instances running GlobalProtect portal or gateway services. If immediate patching is not possible, consider restricting GlobalProtect access to authorized IP ranges as a temporary mitigation.
Security Insight
This authentication bypass is the second PAN-OS vulnerability confirmed exploited in the wild in rapid succession, following CVE-2026-0300 (an RCE in the same GlobalProtect component). The pattern suggests threat actors have invested in reverse-engineering Palo Alto’s VPN stack and are chaining similar-class bugs. Organizations should treat all PAN-OS GlobalProtect interfaces as high-value targets and prioritize patching cycles accordingly, even when individual CVSS scores appear moderate.
For ongoing coverage of this and related threats, see the Weekly Threat Roundup: Critical PAN-OS Flaw Exploited (May 4-10) and PAN-OS RCE CVE-2026-0300 exploited in the wild.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Public PoC References
Unverified third-party code
These repositories are publicly listed on GitHub and have not been audited by Yazoul Security. They may contain malware, backdoors, destructive payloads, or operational security risks (telemetry, exfiltration). Treat them as hostile binaries. Inspect source before execution. Run only in isolated, disposable lab environments (offline VM, no credentials, no production data).
Authorized use only. This information is provided for defensive research, detection engineering, and patch validation. Using exploit code against systems you do not own or do not have explicit written permission to test is illegal in most jurisdictions and violates Yazoul's terms of use.
| Repository | Stars |
|---|---|
| sfewer-r7/CVE-2026-0257 Proof-of-concept script to leverage the PAN-OS GlobalProtect authentication bypass CVE-2026-0257 | ★ 1 |
Showing 1 of 1 known references. Source: nomi-sec/PoC-in-GitHub.
Related Advisories
A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code wi...
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel....
Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthentica...
An authentication bypass vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, enabling any attackers to bypass the authentication requirement and achieve pre-authenticated code execut...