CVE-2026-0257

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

Scoring

Severity
HIGH
CVSS base score
7.8
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/E:A/AU:N/R:A/V:D/RE:M/U:Red
EPSS probability
93.91%
CISA KEV
Known exploited vulnerability
CWE
CWE-565
Published
2026-05-13
Last modified
2026-07-14

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs