CVE-2026-0257: authentication bypass in PAN-OS GlobalProtect, actively exploited
CVE-2026-0257 allows bypassing VPN authentication in PAN-OS GlobalProtect. It is listed in the CISA KEV catalog. What to do today.
CVE-2026-0257: authentication bypass in PAN-OS GlobalProtect, actively exploited
In short
CVE-2026-0257 is an authentication bypass vulnerability in the GlobalProtect portal and gateway of PAN-OS, the system that manages Palo Alto Networks' corporate firewalls and VPNs [1]. An attacker who exploits it can bypass access controls and establish an unauthorized VPN connection into the company's internal network [1]. It has a CVSS score of 7.8, "high" severity according to NVD [1], published on May 13, 2026 [1], and it is listed in CISA's catalog of actively exploited vulnerabilities (KEV) [2], confirming that real-world use by attackers has already been detected. If your organization uses GlobalProtect for remote access, you should today check the version of PAN-OS in use, apply the vendor's patch, and review recent VPN connection logs for anomalous access.
What it is and why it matters
An "authentication bypass" flaw means that the system meant to verify the identity of whoever is connecting can be circumvented, letting traffic through as if it were legitimate [1]. In this specific case, the problem affects the GlobalProtect portal and gateway, Palo Alto Networks' VPN solution that many companies use so their employees can connect remotely to the corporate network [1]. If an attacker manages to establish an unauthorized VPN connection, they gain a foothold inside the network perimeter, with the same level of trust as a legitimate employee connecting remotely. It is worth noting that, according to the vendor's own description, Panorama and Cloud NGFW are not affected by this issue [1]; the focus is on the GlobalProtect portal and gateway.
Who is affected
The primary vendor is Palo Alto Networks, in its PAN-OS product with the GlobalProtect module (portal and gateway) [1]. The NVD entry also associates Siemens as a related vendor with this CVE, but without specifying which product or with what advisory of its own [1]; based on the information available, a specific exposure in Siemens products cannot be confirmed, so we do not treat it as an action item, only as a data point to keep in mind if your company integrates solutions from both vendors.
In practice, all organizations that use GlobalProtect as a VPN entry point for employees, vendors, or remote devices are potentially exposed, especially if the portal is published directly on the internet, which is the typical use case for this type of solution.
How to know if you are vulnerable
The first step is to identify whether your company has a GlobalProtect portal or gateway exposed to the internet and which version of PAN-OS it runs. Being a VPN component, it is usually accessible from outside the corporate network by design, which increases the exposure window until the patch is applied. Checking which of your organization's services are exposed to the internet — and with which software version — is the starting point before deciding on patching priorities; if you don't have that inventory up to date, it's the first gap to close.
As additional reference, our OCIRIA intelligence radar classifies this vulnerability under the category of authentication and unauthorized access, and flags it as a priority concern due to its role at the network perimeter, in line with its inclusion in CISA's KEV catalog [2].
How to protect yourself
- Locate all instances of PAN-OS with GlobalProtect (portal and gateway) in your infrastructure and confirm the installed version.
- Apply the security patch published by Palo Alto Networks as soon as it is available for your version; since this is a vulnerability in the KEV catalog, priority should be high [2].
- Review VPN connection logs from recent weeks for sessions initiated from unusual locations, times, or devices.
- If you detect signs of unauthorized access, consider rotating credentials and reviewing the subsequent activity of those sessions within the network.
- Strengthen VPN access with multi-factor authentication wherever it is not yet enabled, as an additional layer of defense.
- Limit, as much as possible, which internal resources are reachable from a newly established VPN session, to reduce the impact if a connection turns out to be fraudulent.
Frequently asked questions
Is this vulnerability being exploited right now?
Yes, CISA includes it in its catalog of actively exploited vulnerabilities (KEV), which indicates confirmed real-world exploitation [2].
Does it affect Panorama or Cloud NGFW?
No. The technical description itself expressly states that Panorama and Cloud NGFW are not affected by this issue [1].
How severe is it according to official standards?
NVD assigns it a CVSS of 7.8, classified as "high" severity [1]; its presence in CISA's KEV catalog raises the practical urgency to act, regardless of the score [2].
Is having a firewall enough to be protected?
Not necessarily: the problem lies in the VPN component's own authentication, so mitigation requires patching PAN-OS and reviewing access, not just having firewall rules in place.
Sources
- [1] https://nvd.nist.gov/vuln/detail/CVE-2026-0257
- [2] https://raw.githubusercontent.com/cisagov/kev-data/develop/known_exploited_vulnerabilities.json