CVE-2026-0257

● KEV CRITICAL

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorize...

Affects 0 products across 6 vendors.

BCS3.4
CVSS 3.19.1
CVSS v47.8
EPSS93.9%
Percentile100th
PatchUnknown
KEV Added2026-05-29
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, no availability impact.
CWE Weakness Definitions
CWE-565: CWE-565
Related Attack Patterns (CAPEC)
CAPEC-31 Accessing/Intercepting/Modifying HTTP Cookies
via CWE-565
CAPEC-226 Session Credential Falsification through Manipulation
via CWE-565
CAPEC-39 Manipulating Opaque Client-based Data Tokens
via CWE-565

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A low severity vulnerability affects Cloud systems (CVE-2026-0257). No public exploit code is currently available. Review vendor advisories and apply patches during the next maintenance window.

BSID: BS-2026-GLOBAL-059147-I • Model: rule-based-v1 • Confidence: LOW

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-0257?
A low severity vulnerability affects Cloud systems (CVE-2026-0257). No public exploit code is currently available. Review vendor advisories and apply patches during the next maintenance window.
What is the CVSS score for CVE-2026-0257?
CVE-2026-0257 has CVSS 9.1 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N. EPSS: 93.9%.
Is CVE-2026-0257 actively exploited?
Yes. CVE-2026-0257 is in the CISA KEV catalog (added 2026-05-29). Active exploitation confirmed. Immediate patching required.
How do I remediate CVE-2026-0257?
Priority: MONITOR. PSIRT: [email protected]
What systems are affected by CVE-2026-0257?
CVE-2026-0257 affects: Cloud, Fujitsu-Siemens, Gateway, Palo Alto, Palo Alto Networks, Panorama.
Vulnerability Details
CVE IDCVE-2026-0257
BSIDBS-2026-GLOBAL-059147-I BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Published2026-05-13
Last Modified2026-05-29
ICS Relevance65%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues. CVSS vector: Not available.

Exploitation Likelihood: MINIMAL

Affected Products
VendorProductFixed Version
Cloud —
Fujitsu-Siemens —
Gateway —
Palo Alto —
Palo Alto Networks —
Panorama —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 73 Days
CISA KEV● Active Exploitation Confirmed (added 2026-05-29)
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceLOW
Enriched At2026-05-24
SHA-512 Audit Hash5c21212748cf5a9950c6b27be2b7e301c76500edd55fb1ba0df14fbeb78a25c5845510d740d183052c37b7f7c5b8ef657e56a5ed8114a3305c6b1ebaf6576465
Related CVEs affecting Cloud
CVE-2025-54122 10.0 Manager-io/Manager is accounting software. A critical unauthenticated full re... CVE-2025-41243 10.0 Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment p... CVE-2025-64180 10.0 Manager-io/Manager is accounting software. In Manager Desktop and Server vers... CVE-2026-0501 9.9 Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Prem... CVE-2025-47282 9.9 Gardener External DNS Management is an environment to manage external DNS ent...
View all Cloud CVEs →

This Vulnerability Is Being Actively Exploited

CVE-2026-0257 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider alerts your team within 15 minutes when KEV vulnerabilities match your ICS assets.

Start Free KEV Monitoring →