ZeroHour

CVE-2026-0257

KEV ransomwaremass

Authentication Bypass in Palo Alto Networks PAN-OS GlobalProtect Portal and Gateway

CISA: Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

CVSS 4.0
7.8 high
EPSS
95%p100
Published
()
KEV added
AI analysis

CVE-2026-0257 is an authentication bypass in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS that allows a remote, unauthenticated attacker to defeat security restrictions and establish an unauthorized VPN connection; incident reporting indicates it involves forged VPN cookies (CWE-565). An attacker who succeeds gains the network access of a legitimate remote-access user, and Qilin ransomware affiliates have been using this flaw as their initial access vector. Any organization running PAN-OS with the GlobalProtect portal or gateway enabled is in scope, including Siemens RUGGEDCOM APE1808 appliances that run PAN-OS, while Panorama and Cloud NGFW are explicitly not affected. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2026-05-29 with ransomware use known, EPSS assigns it a 93.9% probability of exploitation within 30 days (100th percentile), and Rapid7 has documented attacks against multiple customers.

What to do: Upgrade PAN-OS to the fixed release specified in the Palo Alto Networks security advisory, and check Siemens' guidance if you operate RUGGEDCOM APE1808 appliances. Review GlobalProtect portal/gateway logs for forged VPN cookies and unauthorized VPN sessions, and hunt for Qilin ransomware indicators on hosts reachable through the VPN. If patching cannot happen immediately, restrict internet exposure of the GlobalProtect portal and gateway; federal agencies must apply mitigations per BOD 22-01 given the KEV listing.

Affected
Palo Alto Networks PAN-OS (GlobalProtect portal and gateway)
Palo Alto Networks Prisma AccessListed in CPE data; affected status not detailed in source description, confirm with vendor advisory
Siemens RUGGEDCOM APE1808 firmware
Estimated exposure
massOn the order of hundreds of thousands of internet-exposed GlobalProtect portals/devices (mid-six figures) — PAN-OS is one of the most widely deployed enterprise firewall/VPN platforms and public internet scans have historically shown hundreds of thousands of exposed GlobalProtect portals, so exposure is plausibly in the hundreds of thousands of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

CISA Known Exploited Vulnerability
Affected
Palo Alto Networks PAN-OS
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Known
Vendors
paloaltonetworkssiemens
Products
pan-os, prisma access, ruggedcom ape1808 firmware
Weakness
CWE-565
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:Red

In the news