Authentication bypass in Palo Alto PAN-OS (CVE-2026-0257) — allows unauthorized VPN connections
An authentication-bypass vulnerability in Palo Alto Networks' firewall OS, PAN-OS, lets an attacker bypass security restrictions and establish an unauthorized VPN connection. CISA listed it as known-exploited (KEV) (CVSS 9.1 Critical).
Key facts
- CVE IDCVE-2026-0257
- CVSS base score9.1 CRITICAL
- CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Affected (vendor / product)Palo Alto Networks PAN-OS
- CWECWE-565
- ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
- Remediation due2026-06-01 (U.S. federal civilian agencies, BOD 22-01)
Key points
- Authentication-bypass vulnerability in PAN-OS (the OS for Palo Alto firewall products)
- An attacker can bypass security restrictions and establish an unauthorized VPN connection
- Compromise of a perimeter device = a foothold for internal intrusion. Listed in CISA KEV (CVSS 9.1 Critical)
- Response: apply fixes/mitigations per the vendor advisory (disable the feature / discontinue use if not possible)
- Federal civilian remediation deadline was a short June 1, 2026
- Of the 1,687 KEV records held as of 2026-09-01, edge and remote-access vendors account for 238 — 14 percent.
1A flaw in the next-generation firewall
CVE-2026-0257 is an authentication-bypass vulnerability in PAN-OS, the operating system that runs on Palo Alto Networks next-generation firewall products. It was added to CISA's KEV catalog on May 29, 2026 and is classified as CWE-565 (reliance on cookies without validation and integrity checking).
2Unauthorized VPN sessions being established
When exploited, an attacker bypasses the intended security restrictions and establishes an unauthorized VPN connection. Firewalls / VPN gateways sit at the boundary between the internal network and the outside; breaking through one hands the attacker a foothold for internal intrusion.
Vulnerabilities in perimeter-defense products have repeatedly been exploited as the initial access vector in ransomware and state-linked attacks, so priority is high.
3Edge devices are regulars on KEV
Equipment placed at the boundary between an organisation and the outside — firewalls and VPN gateways — appears on KEV repeatedly. Counted by vendor, the concentration is plain.
Of the 1,687 records held as of 2026-09-01, vendors of edge and remote-access equipment — the above plus Zyxel at 12, F5 at 7 and Check Point at 3 — account for 238, or 14 percent. Vulnerabilities in perimeter products have been used repeatedly as the initial access route in ransomware and state-linked attacks in recent years, which puts them high in priority.
Why it matters
Many organizations place PAN-OS devices at the perimeter, and because they are internet-facing the impact is large. The priorities are asset inventory (knowing which PAN-OS devices are internet-exposed), prompt patching, and reviewing VPN logs.
FAQ
What is PAN-OS?
How dangerous is it?
What should I do?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).