Skip to content
All vulnerabilities
CVE-2026-0257KEVRansomware

PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities

Severity
Critical9.1CVSS 3.1, Critical
Known exploited
Known exploitedFederal remediation due date: 1 Jun 2026
Exploit prediction
96%
Published
13 May 2026Updated 14 Jul 2026 · Last verified 28 Sept 2026

Known remediation

Fixed releases per branch, as the vendor states them. Patcharo never infers a fix.

  • Palo Alto Networks PAN-OS

    Vendor advisory
    • 12.112.1.4-h6, 12.1.7
    • 11.211.2.4-h17, 11.2.7-h14, 11.2.10-h7, 11.2.12
    • 11.111.1.4-h33, 11.1.6-h32, 11.1.7-h6, 11.1.10-h25, 11.1.13-h5, 11.1.15
    • 10.210.2.7-h34, 10.2.10-h36, 10.2.13-h21, 10.2.16-h7, 10.2.18-h6

Workaround / Vendor remediation

Workaround · PAN-OS

Customers can mitigate the risk of this issue by taking any of the following actions: * Use a dedicated certificate for Authentication Override cookies: Generate a new certificate exclusively for authentication override cookies and store it securely. Do not reuse the portal or gateway certificate, and do not share this certificate with other features or users. * Disable Authentication Override: Uncheck the Authentication Override options (for generating and accepting cookies) in the GlobalProtect portal and gateway configuration.

Vendor remediation · PAN-OS

Version Minor Version Suggested Solution Cloud NGFW All No action needed. PAN-OS 12.1 12.1.5 through 12.1.6 Upgrade to 12.1.7 or later. 12.1.2 through 12.1.4-h* Upgrade to 12.1.4-h6 or 12.1.7 or later. PAN-OS 11.2 11.2.11 or later Upgrade to 11.2.12 or later. 11.2.8 through 11.2.10-h* Upgrade to 11.2.10-h7 or 11.2.12 or later. 11.2.5 through 11.2.7-h* Upgrade to 11.2.7-h14 or 11.2.12 or later. 11.2.0 through 11.2.4-h* Upgrade to 11.2.4-h17 or 11.2.12 or later. PAN-OS 11.1 11.1.14 or later Upgrade to 11.1.15 or later. 11.1.11 through 11.1.13-h* Upgrade to 11.1.13-h5 or 11.1.15 or later. 11.1.8 through 11.1.10-h* Upgrade to 11.1.10-h25 or 11.1.15 or later. 11.1.7 through 11.1.7-h* Upgrade to 11.1.7-h6 or 11.1.15 or later. 11.1.5 through 11.1.6-h* Upgrade to 11.1.6-h32 or 11.1.15 or later. 11.1.0 through 11.1.4-h* Upgrade to 11.1.4-h33 or 11.1.15 or later. PAN-OS 10.2 10.2.17 through 10.2.…

Description

Title, description and vendor guidance are quoted from the source records.

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

Weakness: CWE-565

Known exploited

Added to CISA KEV on 29 May 2026

Federal remediation due date: 1 Jun 2026

Known use in ransomware campaigns

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Exploit prediction

96% probability of exploitation in the next 30 days (percentile 100%).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

What the source states, per branch

Versions matched by Patcharo

Palo Alto Networks PAN-OSSource: Palo Alto Networks (CVE record)

BranchAffectedFixed in
12.1
>= 12.1.0, < 12.1.4-h6
>= 12.1.5, < 12.1.7
12.1.4-h6
12.1.7
11.2
>= 11.2.0, < 11.2.4-h17
>= 11.2.5, < 11.2.7-h14
>= 11.2.8, < 11.2.10-h7
>= 11.2.11, < 11.2.12
11.2.4-h17
11.2.7-h14
11.2.10-h7
11.2.12
11.1
>= 11.1.0, < 11.1.4-h33
>= 11.1.5, < 11.1.6-h32
>= 11.1.7, < 11.1.7-h6
>= 11.1.8, < 11.1.10-h25
>= 11.1.11, < 11.1.13-h5
>= 11.1.14, < 11.1.15
11.1.4-h33
11.1.6-h32
11.1.7-h6
11.1.10-h25
11.1.13-h5
11.1.15
10.2
>= 10.2.0, < 10.2.7-h34
>= 10.2.8, < 10.2.10-h36
>= 10.2.11, < 10.2.13-h21
>= 10.2.14, < 10.2.16-h7
>= 10.2.17, < 10.2.18-h6
10.2.7-h34
10.2.10-h36
10.2.13-h21
10.2.16-h7
10.2.18-h6

Versions not listed are stated unaffected by the vendor.

Affected products

  • Palo Alto Networks Prisma Access · 10.2.0 < 10.2.10-h36, 11.2.0 < 11.2.7-h13

References

Provenance

Every fact on this page comes from the sources below. Nothing is written by an AI.

Palo Alto Networks (CVE record)
Palo Alto Networks (CVE record) · 28 Sept 2026 at 21:17 UTC · Parser patcharo-cve5/1.1.0
CISA Known Exploited Vulnerabilities
CISA Known Exploited Vulnerabilities · 28 Sept 2026 at 21:17 UTC · Parser patcharo-kev/1.0.0
NVD
NVD · 27 Sept 2026 at 23:44 UTC · Parser patcharo-nvd/1.0.0
FIRST EPSS
FIRST EPSS · 27 Sept 2026 at 23:46 UTC · Parser patcharo-epss/1.0.0

Last verified: 28 Sept 2026 at 21:17 UTC