CVE-2026-0257
Description
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.
Panorama and Cloud NGFW are not impacted by these issues.
Summary dbcve.org
This is a critical authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect portal and gateway components. The flaw allows unauthenticated attackers to bypass security controls and establish unauthorized VPN connections to the corporate network, potentially granting them full network access as if they were legitimate remote users.
Mitigation
Apply available patches from Palo Alto Networks for affected PAN-OS versions immediately. Review GlobalProtect configuration and monitor for unauthorized VPN connection attempts. Since Panorama and Cloud NGFW are not affected, focus remediation efforts specifically on PAN-OS deployments.