CVE-2026-0257: Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.
How it works
The weakness is identified as CWE-565. In this class of flaw an authentication mechanism fails to enforce required checks, allowing an attacker to reach a protected function without presenting valid proof of identity. For PAN-OS the affected function is the VPN connection process. An attacker who can reach the relevant interface may therefore establish a VPN session that the system should have rejected.
Am I affected? How to find it in your systems
PAN-OS runs on Palo Alto Networks firewalls and appliances that terminate remote-access or site-to-site VPN tunnels. Begin by inventorying every device that runs PAN-OS and noting which ones have any VPN profile enabled. Review configuration exports or management logs for active VPN gateways and associated authentication settings. Telemetry that may indicate attempted abuse includes repeated authentication failures followed by successful session establishment from unexpected source addresses. Exact version numbers and configuration conditions that trigger the flaw must be confirmed against the vendor advisory.
How to remediate
Apply the mitigations listed in the vendor advisory as the primary step. Where PAN-OS instances are used as cloud services, also follow any applicable BOD 22-01 requirements. After the update is installed, verify that VPN authentication settings remain enforced and that no residual sessions exist from before the change. If the advisory indicates that a configuration change is part of the fix, apply and test that change in a maintenance window before returning the device to production.
If you can't patch immediately
Until the vendor update can be applied, reduce exposure by placing affected appliances behind network segmentation that limits inbound VPN traffic to trusted source ranges only. Consider disabling VPN profiles that are not strictly required. Where a web application firewall or virtual patching capability sits in front of the management or VPN interfaces, add rules that drop sessions matching the unauthenticated pattern described in the advisory. Increase logging on authentication events and forward those logs to a central system for anomaly detection. If no effective mitigation is available, discontinue use of the product as stated in the CISA guidance.
If your data may have been exposed
Authentication bypass vulnerabilities that reach exploitation can lead to unauthorized access and subsequent data exposure. Organizations that rely on PAN-OS for VPN should review authentication logs for unexpected successful connections and compare those events against known breach data. A free exposure scan of email addresses can help determine whether related credentials already appear in public breach records.
AICompiled with AI assistance from public sources and published under our editorial standards.