CyberICT

CVE-2026-0257

Palo Alto Networks · Published May 13, 2026

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

Affected Products

  • PAN OS < 10.2.7
  • PAN OS
  • Prisma Access
  • Ruggedcom Ape1808 Firmware

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N