Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3510 articles · 182400 vulns · 37/41 feeds (7d)
← Back to list
7.8
CVE-2026-0257EXPLOITEDPATCHED
palo alto networks · pan-os

PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities

Description

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

Affected Products

VendorProductVersions
palo alto networkspan-os12.1.0, 11.2.0, 11.1.0, 10.2.0, 10.2.0, 11.2.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
palo alto networkspan-oscert_advisory90%
palo alto networksprisma_accesscve_cpe95%
siemensruggedcom_ape1808_firmwarecve_cpe95%
siemensruggedcom_ape1808cve_cpe95%

References

  • https://security.paloaltonetworks.com/CVE-2026-0257(vendor-advisory)

Related News (22 articles)

Tier D
CSO Online6d ago
Ransomware groups are hammering your vulnerable VPNs
→ No new info (linked only)
Tier D
The Hacker News8d ago
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
→ No new info (linked only)
Tier D
BleepingComputer9d ago
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
→ No new info (linked only)
Tier C
Rapid7 Blog16d ago
Rapid7 and Mindshare Partner to Accelerate Cyber Resilience Across the Middle East
→ No new info (linked only)
Tier D
BleepingComputer28d ago
ChocoPoc malware delivered via trojanized exploits on GitHub
→ No new info (linked only)
Tier C
Palo Alto Unit 4244d ago
Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE
→ No new info (linked only)
Tier D
The Hacker News45d ago
Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw
→ No new info (linked only)
Tier D
Help Net Security53d ago
Week in review: Cisco SD-WAN 0-day exploited, Patch Tuesday forecast
→ No new info (linked only)
Tier C
Palo Alto Unit 4254d ago
Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257
→ No new info (linked only)
Tier C
Rapid7 Blog55d ago
How the “Swiss Cheese” model can help you choose the right MDR provider
→ No new info (linked only)
Tier D
CSO Online58d ago
Attackers exploit Palo Alto GlobalProtect flaw days after disclosure
→ No new info (linked only)
Tier D
SecurityWeek59d ago
Recent Palo Alto Networks Vulnerability Exploited for Weeks
→ No new info (linked only)
Tier D
Help Net Security59d ago
Hackers are exploiting Palo Alto GlobalProtect VPN authentication bypass (CVE-2026-0257)
→ No new info (linked only)
Tier D
Infosecurity Magazine59d ago
Palo Alto Warns High-Severity Bug Is Being Actively Exploited
→ No new info (linked only)
Tier D
Heise Security59d ago
Angriffe auf Palo Alto Networks PAN-OS GlobalProtect
→ No new info (linked only)
Tier D
BleepingComputer60d ago
Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks
→ No new info (linked only)
Tier E
Reddit r/cybersecurity61d ago
PAN-OS added to KEV, Langflow exploit activity, and a surprising Windows EPSS jump — today's most actionable vulnerability signals [Threat Intel 2026/5/29}
→ No new info (linked only)
Tier D
The Hacker News61d ago
PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation
→ No new info (linked only)
Tier C
Rapid7 Blog61d ago
Rapid7 Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257)
→ No new info (linked only)
Tier B
BSI Advisories76d ago
[NEU] [hoch] Palo Alto Networks PAN-OS: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR76d ago
Multiples vulnérabilités dans les produits Palo Alto Networks (15 mai 2026)
→ No new info (linked only)
Tier C
VulDB77d ago
CVE-2026-0257 | Palo Alto Cloud NGFW/PAN-OS/Prisma Access GlobalProtect Portal cookie validation
→ No new info (linked only)
CVSS 3.17.8 NONE
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
All12.1.712.1.4-h611.2.1211.2.10-h711.2.7-h1411.2.4-h1711.1.1511.1.13-h511.1.10-h2511.1.7-h611.1.6-h3211.1.4-h3310.2.18-h610.2.16-h710.2.13-h2110.2.10-h3610.2.7-h3410.2.10-h3611.2.7-h13
CWECWE-565
PublishedMay 13, 2026
Last enriched9d agov11
Tags
CVE-2026-0257KEVKnown Exploited VulnerabilitiesCritical VulnerabilityQilin ransomwareArctic WolfRaaS
Trending Score41
Source articles22
Independent13
Info Completeness11/14
Missing: epss, kev, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-0300EXP
PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
Trending: 111
NONECVE-2026-0265
PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled
Trending: 18
NONECVE-2026-0288
PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent
Trending: 17
CRITICALCVE-2026-0284EXP
PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)
Trending: 3
HIGHCVE-2026-0286EXP
PAN-OS: Authenticated Command Injection in CLI
Trending: 3

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 13, 2026
Discovered by ZDM
May 13, 2026
Updated: description, severity, activelyExploited
May 13, 2026
Updated: description, severity, cvssEstimate, iocs, tags
May 29, 2026
Updated: iocs
May 30, 2026
Updated: tags
May 31, 2026
Updated: severity, cvssEstimate, affectedVersions, exploitAvailable, iocs
Jun 1, 2026
Updated: description
Jun 1, 2026
Updated: affectedVersions, tags
Jun 1, 2026
Updated: description, cweIds, tags
Jun 2, 2026
Updated: description, iocs
Jun 5, 2026
Actively Exploited
Jul 14, 2026
Exploit Available
Jul 14, 2026
Patch Available
Jul 14, 2026
Updated: tags
Jul 21, 2026

Version History

v11
Last enriched 9d ago
v11Tier D9d ago

Added MITRE ATT&CK technique T1190 (Exploit Public-Facing Application) and identified Qilin ransomware gang as active threat actor exploiting this vulnerability with multiple confirmed incidents in June 2026.

tags
via BleepingComputer
v10Tier C54d ago

Updated description with more technical detail and added new IoCs for monitoring.

descriptioniocs
via Palo Alto Unit 42
v9Tier D58d ago

Updated description with significant technical details, changed severity to CRITICAL, and added new CWE-287.

descriptioncweIdstags
via CSO Online
v8Tier D59d ago

Updated affected versions with Prisma Access versions, added new IoCs, and included the tag for Known Exploited Vulnerabilities.

affectedVersionstags
via SecurityWeek
v7Tier D59d ago

Updated description with details on exploitation attempts and added CVE-2026-0257 as a tag.

description
via Help Net Security
v6Tier D59d ago

Updated severity to HIGH, CVSS score to 7.8, and added new affected versions including Prisma Access.

severitycvssEstimateaffectedVersionsexploitAvailableiocs
via Heise Security
v5Tier E60d ago

Updated severity to HIGH, marked exploit as available, and added KEV tag.

tags
via Reddit r/cybersecurity
v4Tier D60d ago

Updated severity to HIGH, confirmed active exploitation, and added new IoCs related to the attacks.

iocs
via BleepingComputer
v3Tier C61d ago

Updated description with detailed exploitation information, changed severity to CRITICAL, added CVSS estimate of 7.5, and included new IoCs and tags.

descriptionseveritycvssEstimateiocstags
via Rapid7 Blog
v2Tier C77d ago

Updated description with critical vulnerability details, changed severity to CRITICAL, and noted that no exploit exists.

descriptionseverityactivelyExploited
via VulDB
v177d ago

Initial creation