LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-0257: Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 29, 2026
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jun 1, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-0257 to its Known Exploited Vulnerabilities catalog on May 29, 2026, with a federal patch deadline of Jun 1, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.

This vulnerability in Palo Alto Networks PAN-OS is an authentication bypass that permits attackers to establish an unauthorized VPN connection by circumventing security restrictions. It matters because successful abuse can grant network access that should require valid credentials, increasing the chance of further compromise on systems that rely on PAN-OS for remote connectivity.

How it works

The weakness is identified as CWE-565. In this class of flaw an authentication mechanism fails to enforce required checks, allowing an attacker to reach a protected function without presenting valid proof of identity. For PAN-OS the affected function is the VPN connection process. An attacker who can reach the relevant interface may therefore establish a VPN session that the system should have rejected.

Am I affected? How to find it in your systems

PAN-OS runs on Palo Alto Networks firewalls and appliances that terminate remote-access or site-to-site VPN tunnels. Begin by inventorying every device that runs PAN-OS and noting which ones have any VPN profile enabled. Review configuration exports or management logs for active VPN gateways and associated authentication settings. Telemetry that may indicate attempted abuse includes repeated authentication failures followed by successful session establishment from unexpected source addresses. Exact version numbers and configuration conditions that trigger the flaw must be confirmed against the vendor advisory.

How to remediate

Apply the mitigations listed in the vendor advisory as the primary step. Where PAN-OS instances are used as cloud services, also follow any applicable BOD 22-01 requirements. After the update is installed, verify that VPN authentication settings remain enforced and that no residual sessions exist from before the change. If the advisory indicates that a configuration change is part of the fix, apply and test that change in a maintenance window before returning the device to production.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure by placing affected appliances behind network segmentation that limits inbound VPN traffic to trusted source ranges only. Consider disabling VPN profiles that are not strictly required. Where a web application firewall or virtual patching capability sits in front of the management or VPN interfaces, add rules that drop sessions matching the unauthenticated pattern described in the advisory. Increase logging on authentication events and forward those logs to a central system for anomaly detection. If no effective mitigation is available, discontinue use of the product as stated in the CISA guidance.

If your data may have been exposed

Authentication bypass vulnerabilities that reach exploitation can lead to unauthorized access and subsequent data exposure. Organizations that rely on PAN-OS for VPN should review authentication logs for unexpected successful connections and compare those events against known breach data. A free exposure scan of email addresses can help determine whether related credentials already appear in public breach records.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedPalo Alto Networks · PAN-OS
WeaknessCWE-565
Added to CISA KEVMay 29, 2026
Federal patch deadlineJun 1, 2026
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities