CVE-2026-0257: Palo Alto Networks PAN-OS Authentication Bypass
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability. Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.
- CISA KEV-listed (remediation due 2026-06-01)
- used in ransomware campaigns
- EPSS 95.2% (99.9% percentile)
- CVSS 7.8 high
Related briefings
- Rogue VPN gateway can run code on Palo Alto clients 2026-08-14
- Fake exploit code is stealing security researchers' secrets 2026-08-04
- Hackers exploit SonicWall remote access appliances, CISA warns 2026-07-14
- CISA warns SimpleHelp remote-support bug is under active attack 2026-06-30
- Critical Kemp LoadMaster bug lets hackers run code without a login 2026-06-29