standards
CISA puts first PAN-OS GlobalProtect auth bypass on KEV
CVE-2026-0257 exploits a misconfiguration interplay between authentication override cookies and certificate settings, it can't be firewalled away on the data plane, so patching is the only mitigation.
CISA added CVE-2026-0257, an authentication bypass in PAN-OS GlobalProtect portal and gateway interfaces, to its Known Exploited Vulnerabilities catalog on June 22 based on evidence of active exploitation. The vulnerability affects PAN-OS 10.2, 11.1, and 11.2 across dozens of patch trains when GlobalProtect is configured with authentication override cookies enabled and a specific certificate configuration present. Palo Alto Networks reports limited exploit attempts in the wild. Prisma Access customers are on a managed upgrade schedule; self-managed PAN-OS instances require immediate patching.