CISA puts first PAN-OS GlobalProtect auth bypass on KEV
CVE-2026-0257 exploits a misconfiguration interplay between authentication override cookies and certificate settings, it can't be firewalled away on the data plane, so patching is the only mitigation.
TL;DR
CISA added CVE-2026-0257, an authentication bypass in PAN-OS GlobalProtect portal and gateway interfaces, to its Known Exploited Vulnerabilities catalog on June 22 based on evidence of active exploitation. The vulnerability affects PAN-OS 10.2, 11.1, and 11.2 across dozens of patch trains when GlobalProtect is configured with authentication override cookies enabled and a specific certificate configuration present. Palo Alto Networks reports limited exploit attempts in the wild. Prisma Access customers are on a managed upgrade schedule; self-managed PAN-OS instances require immediate patching.
CVE-2026-0257 is the first PAN-OS GlobalProtect authentication bypass to land on CISA's Known Exploited Vulnerabilities catalog, and it arrives with active exploitation already underway. Palo Alto Networks has confirmed limited exploit attempts against unpatched devices. The vulnerability allows an unauthenticated attacker to bypass authentication on the GlobalProtect portal or gateway and establish an unauthorized VPN connection, opening the door to lateral movement, data exfiltration, and network reconnaissance once inside.
The affected surface is wide. The advisory covers PAN-OS 10.2, 11.1, and 11.2 across at least fifteen patch trains, with the prerequisite that authentication override cookies are enabled and a particular certificate configuration exists. Palo Alto Networks hasn't publicly detailed what that certificate configuration looks like, so organizations running GlobalProtect should assume vulnerability until they've verified their patch state.
The KEV listing carries operational weight for defense contractors. CISA's Binding Operational Directive 22-01 applies to federal civilian agencies, but the KEV catalog also functions as a de facto prioritization signal across the defense industrial base. For contractors managing CUI boundary devices under NIST SP 800-171, a KEV-listed vulnerability with active exploitation on a public-facing VPN appliance leaves little room to argue that patching can wait beyond the next maintenance window.
This isn't a management-interface bug like CVE-2024-0012 or CVE-2025-0108. CVE-2026-0257 sits on the GlobalProtect data plane, the very interface meant to be exposed. You cannot restrict access to trusted IPs and call it mitigated. The patch is the mitigation.
Prisma Access: managed, not immune
Prisma Access customers are covered differently. Palo Alto Networks is actively upgrading all Prisma Access instances on an upgrade schedule shared with customers, but the advisory notes that Prisma Access 11.2.0 below 11.2.7-h13 and 10.2.0 below 10.2.10-h36 are affected. The distinction matters: "being upgraded" is not the same as "already patched." A Prisma Access customer who hasn't received their upgrade window should verify status directly.
What the practitioner does Monday
Identify every PAN-OS firewall running 10.2, 11.1, or 11.2 with GlobalProtect portal or gateway configured. Check whether authentication override cookies are enabled. Then patch. There isn't a configuration workaround described in the advisory that avoids the upgrade. For organizations running fleets of PA-220s or VM-Series on 10.2, the upgrade cycle starts now, staggered by site if you must, but started.
Published ·Deep Fathom