Description
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.
CISA Known Exploited Vulnerability
Date added 2026-05-29 | Due date 2026-06-01
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Problem types
CWE-565 Reliance on Cookies without Validation and Integrity Checking
Product status
All (custom)
12.1.0 (custom) before 12.1.7, 12.1.4-h6
11.2.0 (custom) before 11.2.12, 11.2.10-h7, 11.2.7-h14, 11.2.4-h17
11.1.0 (custom) before 11.1.15, 11.1.13-h5, 11.1.10-h25, 11.1.7-h6, 11.1.6-h32, 11.1.4-h33
10.2.0 (custom) before 10.2.18-h6, 10.2.16-h7, 10.2.13-h21, 10.2.10-h36, 10.2.7-h34
10.2.0 (custom) before 10.2.10-h36
11.2.0 (custom) before 11.2.7-h13
Timeline
| 2026-05-13: | Initial publication. |
| 2026-05-29: | Updated exploitation status. |
Credits
Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue.
References
www.cisa.gov/...nerabilities-catalog?field_cve=CVE-2026-0257
security.paloaltonetworks.com/CVE-2026-0257