What it is
CVE-2026-0257 is an unauthenticated PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities affecting Palo Alto Networks Cloud NGFW and 2 other products. Authentication bypass vulnerabilities in the GlobalProtect...
Vulnerability report
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
Palo Alto Networks / Cloud NGFW · affected before *
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2026-0257 is an unauthenticated PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities affecting Palo Alto Networks Cloud NGFW and 2 other products. Authentication bypass vulnerabilities in the GlobalProtect...
Is it exploited?
Yes. KEV Intelligence tracks this CVE as a known exploited vulnerability. Confidence is confirmed.
Who is affected?
Palo Alto Networks / Cloud NGFW affected before *.
What should we do?
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
Overview
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.
Panorama and Cloud NGFW are not impacted by these issues.
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
CVE
Independent exploitation attestation added to the KEV Intelligence record.
GitHub
Public scanner or PoC coverage increases practical exploitability.
Per-source evidence links for KEV attestations are available through the KEV Intelligence Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| The Shadowserver First | 2026-05-30 07:34 UTC |
| BleepingComputer | 2026-05-30 18:02 UTC |
| CVE | 2026-06-01 10:28 UTC |
| CISA | 2026-06-02 14:00 UTC |
| TheHackerNews | 2026-06-02 14:21 UTC |
| All CISA Advisories | 2026-06-02 14:21 UTC |
| Palo Alto Unit42 | 2026-06-05 14:20 UTC |
Operational indicators for this CVE are listed under Detection.
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Raw values available in Pro and Enterprise.
Nuclei template detected 03 Jun 2026.
View Nuclei template (opens in new tab)No KEV Intelligence virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →Operational indicators linked to exploitation of this CVE. IoCs age over time — especially IP addresses.
| Type | Indicator | First Seen | Last Seen | Age | Source |
|---|---|---|---|---|---|
| IP |
23.128.228.6
|
2026-06-05 17:24 UTC | 2026-06-05 17:24 UTC | 3 months ago | Source |
| IP |
104.207.144.154
|
2026-06-05 17:24 UTC | 2026-06-05 17:24 UTC | 3 months ago | Source |
| IP |
146.19.216.119
|
2026-06-05 17:24 UTC | 2026-06-05 17:24 UTC | 3 months ago | Source |
| IP |
146.19.216.120
|
2026-06-05 17:24 UTC | 2026-06-05 17:24 UTC | 3 months ago | Source |
| IP |
146.19.216.125
|
2026-06-05 17:24 UTC | 2026-06-05 17:24 UTC | 3 months ago | Source |
| IP |
179.43.172.213
|
2026-06-05 17:24 UTC | 2026-06-05 17:24 UTC | 3 months ago | Source |
| IP |
185.195.232.139
|
2026-06-05 17:24 UTC | 2026-06-05 17:24 UTC | 3 months ago | Source |
| IP |
198.12.106.60
|
2026-06-05 17:24 UTC | 2026-06-05 17:24 UTC | 3 months ago | Source |
| IP |
202.144.192.47
|
2026-06-05 17:24 UTC | 2026-06-05 17:24 UTC | 3 months ago | Source |
Scanner and exploit-framework references linked to this CVE.
| Scanner | Reference | Detected |
|---|---|---|
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/javascript/cves/2026/CVE-2026-0257.yaml | 03 Jun 2026 |
| Nessus | https://www.tenable.com/plugins/nessus/314450 | 14 May 2026 |
Risk and context
CVSS v4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/E:A/AU:N/R:A/V:D/RE:M/U:Red
EPSS
93.9%
Recent mention · DarkWebInformer
CVE-2026-0257 is an authentication bypass in the GlobalProtect portal and gateway components of Palo Alto Networks PAN-OS software.
Read full advisoryCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/E:A/AU:N/R:A/V:D/RE:M/U:Red
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Recent mention · DarkWebInformer
Trusting a Cookie It Never Issued: The PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257)DarkWebInformer · 21 Jul 2026
CVE-2026-0257 is an authentication bypass in the GlobalProtect portal and gateway components of Palo Alto Networks PAN-OS software.
Recent mention · TheHackerNews
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial AccessTheHackerNews · 21 Jul 2026
Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway
Recent mention · Daily CyberSecurity
Qilin Ransomware Deployed via Palo Alto GlobalProtect Flaw CVE-2026-0257Daily CyberSecurity · 21 Jul 2026
During June 2026, Arctic Wolf Labs traced several ransomware intrusions to one entry point. Attackers exploited a Palo The post Qilin Ransomware Deployed via Palo Alto GlobalProtect Flaw CVE-2026-0257 appeared first on Daily CyberSecurity.
Recent mention · TheHackerNews
Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN FlawTheHackerNews · 15 Jun 2026
Palo Alto Networks has revealed that it has observed "active exploitation" of a recently disclosed PAN-OS vulnerability by an unknown threat actor to obtain unauthorized access to GlobalProtect portals. The vulnerability in question is CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software that could be exploited by bad
Recent mention · Palo Alto Unit42
Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257Palo Alto Unit42 · 05 Jun 2026
We include indicators of activity and mitigations for PAN-OS vulnerability CVE-2026-0257. The post Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 appeared first on Unit 42.
Recent mention · BleepingComputer
Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacksBleepingComputer · 30 May 2026
Palo Alto Networks is warning that hackers are now exploiting a PAN-OS GlobalProtect authentication bypass flaw, tracked as CVE-2026-0257, in attacks attempting to breach corporate networks. [...]
Recent mention · TheHackerNews
PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active ExploitationTheHackerNews · 30 May 2026
Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-0257 (CVSS score: 7.8), refers to a case of authentication bypass that could be exploited by bad actors to set up VPN connections. "Authentication bypass vulnerabilities in the
Recent mention · Palo Alto Networks Security Advisories
CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities (Severity: HIGH)Palo Alto Networks Security Advisories · 29 May 2026
Recent mention · All CISA Advisories
CISA Adds One Known Exploited Vulnerability to CatalogAll CISA Advisories · 29 May 2026
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-0257 Palo Alto Networks PAN-OS Authentication Bypass Vulnerability This type of vulnerability is a frequent attack vectors for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal...
These PoCs are unverified and could contain malware. Use at your own risk.
nuclei · Created Unknown
Timeline
Public proof-of-concept code published
Indicators of compromise recorded
Exploitation attested by an external source
Scanner coverage available
Exploitation attested by an external source
Exploitation attested by an external source
Listed in the CISA Known Exploited Vulnerabilities catalog
Exploitation attested by an external source
Exploitation attested by an external source
High-confidence, third-party attested exploitation
Scanner coverage available
Vulnerability disclosed publicly
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2026-0257
Free JSON includes basic KEV fields{
"cve_id": "CVE-2026-0257",
"confidence": "Confirmed",
"cvss_score": 7.8,
"cvss_estimated": false,
"epss_score": 0.93905,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "attempts": 0, "sensors": 0 }
}
Early warning alerts
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.