CVE-2026-0257CISA KEV: Actively Exploited

Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

Published May 29, 2026·Updated May 29, 2026

Description

Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.

Public Exploits & PoCs8 found

[POC] CVE-2026-0257 — CVE-2026-0257

GrayXploit Security research and defensive team validate this toolkit for CVE-2026-0257 (PAN-OS GlobalProtect Authentication Bypass). Includes vulnerability assessment, detection guidance, technical analysis, indicators of compromise (IOCs), and remediation validation resources for security teams and defenders.

1

[POC] CVE-2026-0257 — CVE-2026-0257

Palo Alto Networks PAN-OS contains an authentication bypass caused by flaws in the GlobalProtect portal and gateway, letting attackers establish unauthorized VPN connections, exploit requires network access to the portal or gateway.

1

[POC] CVE-2026-0257 — CVE-2026-0257

Proof-of-concept script to leverage the PAN-OS GlobalProtect authentication bypass CVE-2026-0257

1

[POC] CVE-2026-0257 — CVE-2026-0257

testing

[POC] CVE-2026-0257 — CVE-2026-0257

PAN-OS: GlobalProtect Authentication Bypass

[POC] CVE-2026-0257 — CVE-2026-0257

Exploits the CVE-2026-0257 vulnerability by forging a GlobalProtect authentication override cookie using the TLS server's public key.

[POC] CVE-2026-0257 — CVE-2026-0257

CVE-2026-0257

[POC] CVE-2026-0257 — CVE-2026-0257

CVE-2026-0257 - Draft

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free