Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2583 articles · 159762 vulns · 36/41 feeds (7d)
← Back to list
7.8
CVE-2026-0257EXPLOITEDPATCHED
palo alto networks · pan-os

PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities

Description

The flaw allows attackers to establish unauthorized VPN access into corporate networks and is being actively exploited in the wild. Rapid7 observed successful exploitation across numerous customers, with attackers beginning to exploit the bug as early as May 17, four days after Palo Alto published fixes. The vulnerability enables a fully credential-less authentication bypass, allowing attackers to create a forged cookie using a publicly available public key to establish a VPN session without malware or stolen credentials.

Affected Products

VendorProductVersions
palo alto networkspan-os12.1.0, 11.2.0, 11.1.0, 10.2.0, 10.2.0, 11.2.0, 12.1, 11.2, 11.1, 10.2, Prisma Access 10.2, Prisma Access 11.2, Prisma Access 11.2.0, Prisma Access 10.2.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
palo alto networkspan-oscert_advisory90%
palo alto networksprisma_accesscve_cpe95%

References

  • https://security.paloaltonetworks.com/CVE-2026-0257(vendor-advisory)

Related News (13 articles)

Tier C
Rapid7 Blog3h ago
How the “Swiss Cheese” model can help you choose the right MDR provider
→ No new info (linked only)
Tier D
CSO Online2d ago
Attackers exploit Palo Alto GlobalProtect flaw days after disclosure
→ No new info (linked only)
Tier D
SecurityWeek3d ago
Recent Palo Alto Networks Vulnerability Exploited for Weeks
→ No new info (linked only)
Tier D
Help Net Security3d ago
Hackers are exploiting Palo Alto GlobalProtect VPN authentication bypass (CVE-2026-0257)
→ No new info (linked only)
Tier D
Infosecurity Magazine3d ago
Palo Alto Warns High-Severity Bug Is Being Actively Exploited
→ No new info (linked only)
Tier D
Heise Security3d ago
Angriffe auf Palo Alto Networks PAN-OS GlobalProtect
→ No new info (linked only)
Tier D
BleepingComputer4d ago
Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks
→ No new info (linked only)
Tier E
Reddit r/cybersecurity5d ago
PAN-OS added to KEV, Langflow exploit activity, and a surprising Windows EPSS jump — today's most actionable vulnerability signals [Threat Intel 2026/5/29}
→ No new info (linked only)
Tier D
The Hacker News5d ago
PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation
→ No new info (linked only)
Tier C
Rapid7 Blog6d ago
Rapid7 Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257)
→ No new info (linked only)
Tier B
BSI Advisories20d ago
[NEU] [hoch] Palo Alto Networks PAN-OS: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR20d ago
Multiples vulnérabilités dans les produits Palo Alto Networks (15 mai 2026)
→ No new info (linked only)
Tier C
VulDB21d ago
CVE-2026-0257 | Palo Alto Cloud NGFW/PAN-OS/Prisma Access GlobalProtect Portal cookie validation
→ No new info (linked only)
CVSS 3.17.8 HIGH
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
All12.1.712.1.4-h611.2.1211.2.10-h711.2.7-h1411.2.4-h1711.1.1511.1.13-h511.1.10-h2511.1.7-h611.1.6-h3211.1.4-h3310.2.18-h610.2.16-h710.2.13-h2110.2.10-h3610.2.7-h3410.2.10-h3611.2.7-h13
CWECWE-565, CWE-287
PublishedMay 13, 2026
Last enriched2d agov9
Tags
CVE-2026-0257KEVKnown Exploited VulnerabilitiesCritical Vulnerability
Trending Score106🔥
Source articles13
Independent12
Info Completeness11/14
Missing: epss, kev, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-0300EXP
PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
Trending: 85
NONECVE-2026-0264
PAN-OS: Heap-Based Buffer Overflow in DNS Proxy and DNS Server Allows Unauthenticated Remote Code Execution
Trending: 5
NONECVE-2026-0265
PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled
Trending: 5
NONECVE-2026-0263
PAN-OS: Remote Code Execution (RCE) in IKEv2 Processing
Trending: 5
HIGHCVE-2026-0250EXP
GlobalProtect App: Buffer Overflow Vulnerability during connection to Portal or Gateway
Trending: 4

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 13, 2026
Discovered by ZDM
May 13, 2026
Updated: description, severity, activelyExploited
May 13, 2026
Updated: description, severity, cvssEstimate, iocs, tags
May 29, 2026
Actively Exploited
May 30, 2026
Exploit Available
May 30, 2026
Patch Available
May 30, 2026
Updated: iocs
May 30, 2026
Updated: tags
May 31, 2026
Updated: severity, cvssEstimate, affectedVersions, exploitAvailable, iocs
Jun 1, 2026
Updated: description
Jun 1, 2026
Updated: affectedVersions, tags
Jun 1, 2026
Updated: description, cweIds, tags
Jun 2, 2026

Version History

v9
Last enriched 2d ago
v9Tier D2d ago

Updated description with significant technical details, changed severity to CRITICAL, and added new CWE-287.

descriptioncweIdstags
via CSO Online
v8Tier D3d ago

Updated affected versions with Prisma Access versions, added new IoCs, and included the tag for Known Exploited Vulnerabilities.

affectedVersionstags
via SecurityWeek
v7Tier D3d ago

Updated description with details on exploitation attempts and added CVE-2026-0257 as a tag.

description
via Help Net Security
v6Tier D3d ago

Updated severity to HIGH, CVSS score to 7.8, and added new affected versions including Prisma Access.

severitycvssEstimateaffectedVersionsexploitAvailableiocs
via Heise Security
v5Tier E4d ago

Updated severity to HIGH, marked exploit as available, and added KEV tag.

tags
via Reddit r/cybersecurity
v4Tier D4d ago

Updated severity to HIGH, confirmed active exploitation, and added new IoCs related to the attacks.

iocs
via BleepingComputer
v3Tier C5d ago

Updated description with detailed exploitation information, changed severity to CRITICAL, added CVSS estimate of 7.5, and included new IoCs and tags.

descriptionseveritycvssEstimateiocstags
via Rapid7 Blog
v2Tier C21d ago

Updated description with critical vulnerability details, changed severity to CRITICAL, and noted that no exploit exists.

descriptionseverityactivelyExploited
via VulDB
v121d ago

Initial creation