CRITICAL

CVE-2026-0257

Paloaltonetworks Pan Os 2026-05-13 CVSS v3.1
CVSS
9.1
KEV

Description

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.

Panorama and Cloud NGFW are not impacted by these issues.

Summary dbcve.org

This is a critical authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect portal and gateway components. The flaw allows unauthenticated attackers to bypass security controls and establish unauthorized VPN connections to the corporate network, potentially granting them full network access as if they were legitimate remote users.

Mitigation

Apply available patches from Palo Alto Networks for affected PAN-OS versions immediately. Review GlobalProtect configuration and monitor for unauthorized VPN connection attempts. Since Panorama and Cloud NGFW are not affected, focus remediation efforts specifically on PAN-OS deployments.

Weakness (CWE)

CWE-565

EPSS Score

95.16%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE