Knox CVE Database
/
CVE-2026-0257
Critical
9.1
Ransomware use

CVE-2026-0257: Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.

Added to the CISA KEV catalog:
May 29, 2026

Overview

PAN-OS firewalls running GlobalProtect accept authentication override cookies without properly validating their integrity, allowing an unauthenticated remote attacker to present a forged cookie and establish an unauthorized VPN connection. The flaw is present in PAN-OS 10.2, 11.1, 11.2, and 12.1 release lines, as well as Prisma Access 10.2 and 11.2, when authentication override cookie acceptance is enabled alongside a specific certificate configuration. Exploitation has been observed in the wild and is associated with known ransomware activity.

Vulnerability details

Affected vendor
Palo Alto Networks
Affected product
PAN-OS
Weakness type (CWE)
CWE-565

PAN-OS implements an authentication override mechanism for GlobalProtect that issues cookies to authenticated users, allowing subsequent connections to skip full credential re-verification. The weakness (CWE-565) is that the portal and gateway accept these cookies without sufficient integrity or authenticity checking. When an attacker submits a crafted or forged cookie, the firewall treats it as valid and grants access without requiring real credentials. The flaw is only present when authentication override cookie acceptance is enabled in the portal or gateway configuration and a specific certificate configuration exists.


An attacker with network access to the GlobalProtect portal or gateway sends a forged authentication override cookie in an inbound connection request. No prior authentication, no user interaction, and no elevated privileges are required. The firewall accepts the cookie and grants the attacker an unauthorized VPN tunnel into the target network, bypassing all authentication restrictions on the GlobalProtect endpoint. Palo Alto Networks has confirmed limited active exploitation against unpatched devices, and this vulnerability is associated with known ransomware use, making rapid remediation critical.

Severity and impact

9.1
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
None

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Known

Detection and monitoring

  • Review GlobalProtect authentication logs for VPN sessions that lack a corresponding initial credential-authentication event in the same session window. A valid override cookie should always follow a prior authenticated session; sessions with no matching login record are anomalous.
  • Monitor for VPN connections from source IP addresses or geographic regions outside the organization's expected user population, particularly where the session was established via cookie override rather than interactive authentication, as forged cookies produce no credential-validation log entry.

Remediation

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Federal (FCEB) remediation due date
June 1, 2026

Additional hardening

  • Upgrade PAN-OS to the fixed release for your branch: 12.1.4-h6 or 12.1.7 for the 12.1 line, 11.2.4-h17, 11.2.7-h14, 11.2.10-h7, or 11.2.12 for 11.2. See the vendor advisory in References for all 10.2 and 11.1 boundaries and Prisma Access targets.
  • If immediate patching is not possible, disable both 'Generate cookie for authentication override' and 'Accept cookie for authentication override' in all GlobalProtect portal and gateway agent configuration profiles to remove the vulnerable code path entirely.
  • Replace any shared or general-purpose certificate used for authentication override cookies with a dedicated certificate issued exclusively for that purpose, reducing the risk that a certificate used elsewhere can be abused to forge valid cookies.
  • Restrict network access to GlobalProtect portal and gateway interfaces to known user IP ranges or VPN concentrator addresses where operationally feasible, reducing the attacker's ability to reach the vulnerable endpoint from arbitrary internet sources.

Key dates

Published (NVD)
May 13, 2026
Added to CISA KEV
May 29, 2026
Remediation deadline
June 1, 2026
Last updated
June 17, 2026

References

Frequently asked questions

Does CVE-2026-0257 affect my FedRAMP authorization?

If Palo Alto Networks PAN-OS runs inside your authorization boundary, yes. CVE-2026-0257 appears in CISA's Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of June 1, 2026, a date that has already passed. For a FedRAMP-authorized service, an unpatched KEV in the boundary is a finding. An overdue one is a finding your assessor and sponsoring agency can see right now. Remediate it or formally document the mitigation and the delay.

How does Knox help me handle CVE-2026-0257?

Knox does not patch your software. Remediating Palo Alto Networks PAN-OS is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, along with continuous compliance monitoring and audit-artifact coverage that support documentation for your next assessment. Applying the fix is yours to do. Managing the compliance posture around it is not something you have to handle on your own.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. When something like CVE-2026-0257 surfaces, exposure appears during continuous monitoring rather than waiting to be flagged at assessor review. That gap between disclosure and discovery closes considerably.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

CVE-2026-0257's remediation deadline of June 1, 2026 has passed. What happens now?

If CVE-2026-0257 remains unremediated, it is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing the finding out and documenting why the deadline was missed is what keeps your authorization intact and the agency relationship in good standing.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.