Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.
PAN-OS firewalls running GlobalProtect accept authentication override cookies without properly validating their integrity, allowing an unauthenticated remote attacker to present a forged cookie and establish an unauthorized VPN connection. The flaw is present in PAN-OS 10.2, 11.1, 11.2, and 12.1 release lines, as well as Prisma Access 10.2 and 11.2, when authentication override cookie acceptance is enabled alongside a specific certificate configuration. Exploitation has been observed in the wild and is associated with known ransomware activity.
PAN-OS implements an authentication override mechanism for GlobalProtect that issues cookies to authenticated users, allowing subsequent connections to skip full credential re-verification. The weakness (CWE-565) is that the portal and gateway accept these cookies without sufficient integrity or authenticity checking. When an attacker submits a crafted or forged cookie, the firewall treats it as valid and grants access without requiring real credentials. The flaw is only present when authentication override cookie acceptance is enabled in the portal or gateway configuration and a specific certificate configuration exists.
An attacker with network access to the GlobalProtect portal or gateway sends a forged authentication override cookie in an inbound connection request. No prior authentication, no user interaction, and no elevated privileges are required. The firewall accepts the cookie and grants the attacker an unauthorized VPN tunnel into the target network, bypassing all authentication restrictions on the GlobalProtect endpoint. Palo Alto Networks has confirmed limited active exploitation against unpatched devices, and this vulnerability is associated with known ransomware use, making rapid remediation critical.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If Palo Alto Networks PAN-OS runs inside your authorization boundary, yes. CVE-2026-0257 appears in CISA's Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of June 1, 2026, a date that has already passed. For a FedRAMP-authorized service, an unpatched KEV in the boundary is a finding. An overdue one is a finding your assessor and sponsoring agency can see right now. Remediate it or formally document the mitigation and the delay.
Knox does not patch your software. Remediating Palo Alto Networks PAN-OS is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, along with continuous compliance monitoring and audit-artifact coverage that support documentation for your next assessment. Applying the fix is yours to do. Managing the compliance posture around it is not something you have to handle on your own.
Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. When something like CVE-2026-0257 surfaces, exposure appears during continuous monitoring rather than waiting to be flagged at assessor review. That gap between disclosure and discovery closes considerably.
Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.
If CVE-2026-0257 remains unremediated, it is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing the finding out and documenting why the deadline was missed is what keeps your authorization intact and the agency relationship in good standing.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.









_Horizontal_RGB.png)








