CVE detail
CVE-2026-0257
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 4.6
Why it matters now
Mention timeline
- Total mentions
- 8
- within the 30d window
- Peak daily
- 3
- highest bucket
Evidence
Source links by recency
24 source links · newest first
lized AI Model for Vulnerability Hunting Check Point patches actively exploited SmartConsole authentication bypass flaw CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities cata
newssecurityaffairs.comJul 26, 2026, 11:42 AMd AI Model for Vulnerability Hunting | Check Point patches actively exploited SmartConsole authentication bypass flaw | CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections | Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft | U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities
newssecurityaffairs.comJul 25, 2026, 8:11 PMlto Networks firewall and VPN appliances to deploy the Qilin ransomware strain. A critical authentication bypass flaw ( CVE-2026-0257 ) in Palo Alto GlobalProtect portal and gateway was the common link in a series of intrusions in June, Arctic Wolf Labs warns. Exploitation of the vulnerability came within days of disclosure . “Post-exploitation tradec
newswww.csoonline.comJul 24, 2026, 7:00 AM- Google Released Gemini 3.5 Flash Cyber AI, a Specialized AI Model for Vulnerability HuntingSecurity Affairs
d AI Model for Vulnerability Hunting | Check Point patches actively exploited SmartConsole authentication bypass flaw | CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections | Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft | U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities
newssecurityaffairs.comJul 23, 2026, 11:44 AM d AI Model for Vulnerability Hunting | Check Point patches actively exploited SmartConsole authentication bypass flaw | CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections | Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft | U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities
newssecurityaffairs.comJul 22, 2026, 8:51 AM- Zimbra 10.1.20 patches multiple security issues, including a critical command injection bugSecurity Affairs
d AI Model for Vulnerability Hunting | Check Point patches actively exploited SmartConsole authentication bypass flaw | CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections | Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft | U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities
newssecurityaffairs.comJul 21, 2026, 6:25 PM Qilin ransomware exploits the PAN-OS GlobalProtect flaw CVE-2026-0257 to gain unauthorized VPN access to unpatched networks. Arctic Wolf researchers warn that the Qilin ransomware gang is exploiting the critical PAN-OS GlobalProtect vulnerability CVE-2026-0257 to compromise corporate netw
newssecurityaffairs.comJul 21, 2026, 4:08 PMnvironments. Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway
newsthehackernews.comJul 21, 2026, 2:04 PMA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Inside GentleKiller: The EDR-Killer Powering The Gentlemen FortiBleed Exposes Global Credential-Spraying Operation CISA Warns of Active […]
newssecurityaffairs.comJun 21, 2026, 5:19 PMWatchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 Related Cloud Cybersecurity Research Resources Threat Research January 20, 2026 DNS OverDoS: Are Private Endpoints Too Private? Microsoft Azure Networking Read now Threat Research October 24, 2025 Cloud Discovery With A
vendorunit42.paloaltonetworks.comJun 16, 2026, 10:00 AM- Palo Alto Warns of Exploitation of VPN Bypass Exploits (CVE-2026-0257) in PAN-OS FlawSecurity Affairs
Palo Alto Networks warns that attackers are actively exploiting CVE-2026-0257, a PAN-OS flaw that lets unauthorized users bypass authentication and establish VPN connections. Palo Alto Networks has confirmed active exploitation of CVE-2026-0257, a PAN-OS authentication bypass vulnerability affecting GlobalProtect portals and gateways. Palo Alto Networks addressed the vulnerability on May 13. Two weeks later, cybersecurity firm Rapid7 […]
newssecurityaffairs.comJun 15, 2026, 11:11 AM We include indicators of activity and mitigations for PAN-OS vulnerability CVE-2026-0257. The post Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 appeared first on Unit 42 .
vendorunit42.paloaltonetworks.comJun 9, 2026, 2:05 PMA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. U.S. CISA adds SolarWinds Serv-U flaw to its Known Exploited Vulnerabilities catalog Report: Anthropic Deploys Engineers […]
newssecurityaffairs.comJun 7, 2026, 2:39 PM- Week in review: Cisco SD-WAN 0-day exploited, Patch Tuesday forecastHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: OWASP Agent Memory Guard: Stop AI agents from being weaponized through their own memory Agent Memory Guard is an open-source runtime defense layer that sits between an agent and its memory store, screening every read and write through a pipeline of detectors and a YAML policy. The project is the OWASP reference implementation for ASI06, Memory Poisoning, one entry in … More →
newswww.helpnetsecurity.comJun 7, 2026, 8:00 AM - CVE-2026-0257Horizon3.ai
CVE-2026-0257 is a critical authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect that allows unauthorized VPN access and is actively exploited in the wild.
exploithorizon3.aiJun 5, 2026, 7:41 PM A Palo Alto Networks vulnerability that allows attackers to establish unauthorized VPN access into corporate networks is being actively exploited in the wild, weeks after the company disclosed the flaw as a medium-severity issue and said it was unaware of any attacks. However, according to Rapid7, threat actors began exploiting the bug within days of […]
newswww.csoonline.comJun 2, 2026, 11:17 AM- 1st June – Threat Intelligence ReportCheck Point Research
en code scanning across the products. The release addresses vulnerabilities in Check Point security gateways, including CVE-2026-48131 and CVE-2026-48132. The vulnerabilities were not exploited in the wild. Check Point IPS provides protection against these threats ( IKE Unsigned Underflow (CVE-2026-48131), IKE Improper Length Validation (CVE-2026-48132
vendorresearch.checkpoint.comJun 1, 2026, 2:43 PM Hackers began exploiting CVE-2026-0257, an authentication bypass in Palo Alto Networks PAN-OS, four days after public disclosure.
newswww.securityweek.comJun 1, 2026, 10:00 AM- Hackers are exploiting Palo Alto GlobalProtect VPN authentication bypass (CVE-2026-0257)Help Net Security
Authentication bypass vulnerabilities (CVE-2026-0257) in Palo Alto Networks’ firewalls that the company disclosed on May 13 have been targeted in “limited exploit attempts”. “Across multiple customers, Rapid7 observed successful exploitation via authentication probes using forged cookies, but the appliance accepted the cookie without a full VPN session being established in 8 out of 10 impacted [Managed Detection Response] customers.” The good news, though, is that the company hasn’t observed any indication of successful lateral movement … More →
newswww.helpnetsecurity.comJun 1, 2026, 9:40 AM - U.S. CISA adds Palo Alto Networks PAN-OS flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Palo Alto Networks PAN-OS flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Palo Alto Networks PAN-OS flaw, tracked as CVE-2026-0257 (CVSS score of 7.8), to its Known Exploited Vulnerabilities (KEV) catalog. Palo Alto Networks addressed the vulnerability CVE-2026-0257 on May […]
newssecurityaffairs.comJun 1, 2026, 8:36 AM - CVE-2026-0257: Rapid7 Caught Attackers Abusing Forged VPN Cookies Against Multiple CustomersSecurity Affairs
CVE-2026-0257 lets attackers forge Palo Alto GlobalProtect auth cookies and bypass VPN login. Exploitation confirmed since May 17. Palo Alto Networks addressed the vulnerability CVE-2026-0257 on May 13. Two weeks later, cybersecurity firm Rapid7 confirmed active exploitation across multiple customer environments. The flaw impacts the GlobalProtect portal and gateway components of Palo Alto Networks PAN-OS […]
newssecurityaffairs.comMay 31, 2026, 5:52 PM No excerpt available.
Mitigationwww.cisa.govMay 13, 2026, 7:17 PM- https://cert-portal.siemens.com/productcert/html/ssa-967325.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comMay 13, 2026, 7:17 PM - https://security.paloaltonetworks.com/CVE-2026-0257security.paloaltonetworks.com
No excerpt available.
Exploitsecurity.paloaltonetworks.comMay 13, 2026, 7:17 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.80 · max 1 stars
- amnsecurity/CVE-2026-0257-GlobalProtect-BypassMedium confidencegithubRepository topic discovery1 starsDiscovered Jul 16, 2026, 12:51 PM
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-0262CVSS 6.6 · Medium
Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) conditio…
- CVE-2026-0261CVSS 6.1 · Medium
Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator to bypass system restrictions and run arbitrary commands as…
- CVE-2026-0258CVSS 4.8 · Medium
A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to s…
- CVE-2026-0256CVSS 4.4 · Medium
A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the we…
- CVE-2026-0265CVSS 7.2 · High
An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to bypass authentication controls when Cloud…
- CVE-2026-0264CVSS 7.2 · High
A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software allows an unauthenticated attacker with network access to cause a d…