Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.
| Vendor | Product | Versions |
|---|---|---|
| palo alto networks | pan-os | 12.1.0, 11.2.0, 11.1.0, 10.2.0, 10.2.0, 11.2.0 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| palo alto networks | pan-os | cert_advisory | 90% |
| palo alto networks | prisma_access | cve_cpe | 95% |
| siemens | ruggedcom_ape1808_firmware | cve_cpe | 95% |
| siemens | ruggedcom_ape1808 | cve_cpe | 95% |
Added MITRE ATT&CK technique T1190 (Exploit Public-Facing Application) and identified Qilin ransomware gang as active threat actor exploiting this vulnerability with multiple confirmed incidents in June 2026.
Updated description with more technical detail and added new IoCs for monitoring.
Updated description with significant technical details, changed severity to CRITICAL, and added new CWE-287.
Updated affected versions with Prisma Access versions, added new IoCs, and included the tag for Known Exploited Vulnerabilities.
Updated description with details on exploitation attempts and added CVE-2026-0257 as a tag.
Updated severity to HIGH, CVSS score to 7.8, and added new affected versions including Prisma Access.
Updated severity to HIGH, marked exploit as available, and added KEV tag.
Updated severity to HIGH, confirmed active exploitation, and added new IoCs related to the attacks.
Updated description with detailed exploitation information, changed severity to CRITICAL, added CVSS estimate of 7.5, and included new IoCs and tags.
Updated description with critical vulnerability details, changed severity to CRITICAL, and noted that no exploit exists.
Initial creation