CVE-2026-0257: Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
Critical severity, CVSS 9.1. Actively exploited: in CISA KEV since 2026-05-29. EPSS: 96.9% chance of exploitation in the next 30 days.
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.
Affected products
- Palo Alto Networks PAN-OS: before 10.2.7 (fixed in 10.2.7); version 10.2.7 only; version 10.2.8 only; version 10.2.9 only; version 10.2.10 only; version 10.2.11 only; …
- Palo Alto Networks Prisma Access: affected versions not specified
- Siemens Ruggedcom APE1808 Firmware: affected versions not specified
Published 2026-05-13. Last modified 2026-06-17.