CVE Database
/

CVE-2026-0257

Back to search

CVE-2026-0257

Published: May 13, 2026

Modified: May 30, 2026

PUBLISHED

Description

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

VendorProductVersions

Palo Alto Networks

Cloud NGFW

unaffected
All

Palo Alto Networks

PAN-OS

affected
12.1.0 - < 12.1.7, 12.1.4-h6
affected
11.2.0 - < 11.2.12, 11.2.10-h7, 11.2.7-h14, 11.2.4-h17
affected
11.1.0 - < 11.1.15, 11.1.13-h5, 11.1.10-h25, 11.1.7-h6, 11.1.6-h32, 11.1.4-h33
affected
10.2.0 - < 10.2.18-h6, 10.2.16-h7, 10.2.13-h21, 10.2.10-h36, 10.2.7-h34

Palo Alto Networks

Prisma Access

affected
10.2.0 - < 10.2.10-h36
affected
11.2.0 - < 11.2.7-h13

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now