CVE-2026-0257: Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

Critical severity, CVSS 9.1. Actively exploited: in CISA KEV since 2026-05-29. EPSS: 96.9% chance of exploitation in the next 30 days.

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

Affected products

  • Palo Alto Networks PAN-OS: before 10.2.7 (fixed in 10.2.7); version 10.2.7 only; version 10.2.8 only; version 10.2.9 only; version 10.2.10 only; version 10.2.11 only; …
  • Palo Alto Networks Prisma Access: affected versions not specified
  • Siemens Ruggedcom APE1808 Firmware: affected versions not specified

Published 2026-05-13. Last modified 2026-06-17.