Junglewise Threat Intelligence

CVE-2026-0257: Palo Alto Networks PAN-OS auth bypass in GlobalProtect

CVE-2026-0257 · Severity: critical · CVSS 4.7 · Exploited in the wild · Published 2026-05-13

Technologies: Palo Alto Networks Prisma Access. Vendors: Palo Alto Networks.

Executive brief

Palo Alto Networks PAN-OS, the operating system used in enterprise firewalls and security appliances, contains a vulnerability that allows attackers to bypass authentication. This could allow an unauthorized user to gain administrative access to the device, potentially leading to full control over network traffic and security policies. CISA has confirmed this vulnerability is being actively exploited in the wild.

Technical details

An authentication bypass vulnerability exists in Palo Alto Networks PAN-OS. While specific technical root causes (such as improper validation or logic errors) are not detailed in the CISA advisory, the flaw allows a remote attacker to bypass security controls. This vulnerability is significant as it affects the core operating system of network security appliances. CISA has added this to the Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. Users are advised to follow vendor guidance for patching and remediation.

Affected products

  • Palo Alto Networks PAN-OS

Timeline

  • 2026-05-29: advisory: CISA added the vulnerability to the Known Exploited Vulnerabilities catalog.
  • 2026-05-29: kev added

References

Related threats