Palo Alto PAN-OS CVE-2026-0257: GlobalProtect Authentication Bypass Under Active Exploit
CISA has added a critical Palo Alto Networks PAN-OS authentication bypass vulnerability to its Known Exploited Vulnerabilities catalog. CVE-2026-0257 affects GlobalProtect portal and gateway configurations, and it is already being exploited in the wild. Therefore, organizations running affected firewall versions must act quickly to secure their remote access infrastructure.
What Happened: Palo Alto GlobalProtect Authentication Bypass Under Active Attack
Palo Alto Networks disclosed CVE-2026-0257 as an authentication bypass flaw in PAN-OS software. The vulnerability exists when GlobalProtect portal or gateway is configured with authentication override cookies enabled and a specific certificate configuration is present. Consequently, unauthenticated remote attackers can bypass security restrictions and establish unauthorized VPN connections.
Palo Alto Networks confirmed limited exploit attempts against unpatched devices on May 29, 2026. In response, CISA added the flaw to its Known Exploited Vulnerabilities catalog with a mandatory patching deadline of June 1, 2026, for federal agencies. Moreover, private sector organizations should treat this timeline as an urgent signal to audit their GlobalProtect deployments immediately.
Technical Details of the Palo Alto PAN-OS Vulnerability
CVE-2026-0257 is an improper access control vulnerability that undermines the authentication boundary between untrusted internet users and internal VPN resources. The issue specifically manifests when administrators have enabled authentication override cookies for GlobalProtect portal or gateway endpoints.
The vulnerability allows attackers to circumvent the normal authentication flow. Furthermore, successful exploitation grants the attacker an unauthorized VPN session, effectively placing them inside the protected network perimeter without valid credentials.
Affected Configurations and Versions
- Firewalls with GlobalProtect portal or gateway configured
- Authentication override cookies enabled in Client Settings
- A specific certificate configuration present on the device
- PAN-OS versions 10.2, 11.1, 11.2, and 12.1 (numerous sub-versions)
Palo Alto Networks has released security updates that regenerate authentication override cookies using a more secure method. Therefore, GlobalProtect users will need to re-authenticate once after the upgrade. This one-time requirement is expected behavior after patching.
Business and Operational Impact
The real-world consequences of CVE-2026-0257 extend beyond the firewall itself. An unauthorized VPN connection can provide attackers with a direct tunnel into sensitive corporate networks. Moreover, this access can be leveraged for lateral movement, data exfiltration, or ransomware deployment.
- Unauthorized network access: Attackers gain VPN connectivity without credentials
- Lateral movement risk: Compromised VPN sessions enable broader network traversal
- Data exposure: Internal resources become reachable from an untrusted origin
- Compliance implications: Failed authentication controls may trigger audit findings
- Reputation damage: Public disclosure of exploitation can erode customer trust
Mitigation and Recommendations
Organizations should prioritize patching affected PAN-OS instances. However, if immediate patching is not feasible, temporary mitigations are available.
Immediate Actions for Defenders
- Apply the latest PAN-OS hotfixes from Palo Alto Networks for affected versions
- Verify GlobalProtect portal and gateway configurations for authentication override cookie settings
- Review VPN logs for anomalous session establishment without preceding authentication events
- Monitor firewall dashboards for unauthorized configuration changes
- Alert security teams to the June 1, 2026, CISA KEV deadline
Workarounds Before Patching
Administrators can reduce exposure by reviewing the authentication override settings in GlobalProtect gateway and portal configurations. Disabling the cookie acceptance for authentication override removes one of the prerequisites for exploitation. Furthermore, limiting internet exposure of GlobalProtect portals to known IP ranges via geo-restriction or perimeter controls can reduce the attack surface.
Bottom line: CVE-2026-0257 is actively exploited and carries a federal patching deadline of June 1, 2026. Patch now, audit your GlobalProtect authentication settings, and monitor VPN logs for unauthorized sessions.
Incident Summary
| CVE ID / Incident: | CVE-2026-0257 |
| Affected Systems: | Palo Alto Networks PAN-OS firewalls with GlobalProtect portal or gateway configured |
| Disclosure Date: | May 29, 2026 |
| Patch Status: | Updates available; CISA KEV due date June 1, 2026 |
| Severity: | Critical (authentication bypass, unauthorized VPN access) |
| Exploitation: | Limited active exploitation confirmed by vendor |
References
- Palo Alto Networks, “CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities,” May 2026, https://security.paloaltonetworks.com/CVE-2026-0257, accessed May 30, 2026.
- CISA, “Known Exploited Vulnerabilities Catalog: CVE-2026-0257,” May 29, 2026, https://www.cisa.gov/known-exploited-vulnerabilities-catalog, accessed May 30, 2026.
- National Vulnerability Database, “NVD – CVE-2026-0257,” https://nvd.nist.gov/vuln/detail/CVE-2026-0257, accessed May 30, 2026.