boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Monday, October 5, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-0257

Palo Alto Networks Cloud NGFW — PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    7.8   .9638   99.9   YES
AFFECTED
  Product        Versions     Fixed
  Cloud NGFW     unspecified  All
  PAN-OS         12.1.0 –     12.1.7
  Prisma Access  10.2.0 –     10.2.10-h36
TIMELINE
  Nov 3   Reserved by palo_alto
  May 13  Published (CNA: palo_alto)
  May 29  Added to CISA KEV, remediation due 2026-06-01
  Jun 2   DUE DATE PASSED — CVE-2026-0257 (Palo Alto Networks PAN-OS). CISA remediation deadline was June 1, 2026; still in catalog.
CWE-565 · CNA: palo_alto · CVSS v4.0 · 3 references · KEV due June 1, 2026

Description

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

Lifecycle

Complete event history — 4 events, chronological
DateEventDetail
November 3, 2025ReservedReserved by palo_alto
May 13, 2026PublishedPublished (CNA: palo_alto)
May 29, 2026KEV ADDEDAdded to CISA KEV, remediation due 2026-06-01
June 2, 2026DUE DATE PASSEDDUE DATE PASSED — CVE-2026-0257 (Palo Alto Networks PAN-OS). CISA remediation deadline was June 1, 2026; still in catalog.

Affected

Affected products and packages — 3 rows
VendorProduct / PackageEcosystemVersion introducedFixed
Palo Alto NetworksCloud NGFW——All
Palo Alto NetworksPAN-OS—12.1.012.1.7
Palo Alto NetworksPrisma Access—10.2.010.2.10-h36

Weaknesses

CWE-565

References (3)

Related

Authoritative record: CVE-2026-0257 at cve.org

Vendors: palo alto networks

Weaknesses: CWE-565

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-0257 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Monday, October 5, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.