Executive Summary
In May 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability affects the GlobalProtect portal and gateway components of Palo Alto Networks' PAN-OS software, allowing unauthenticated attackers to bypass security restrictions and establish unauthorized VPN connections. The flaw is present in multiple versions of PAN-OS, with patches available for affected systems. Organizations using vulnerable versions are urged to apply the necessary updates promptly to mitigate potential risks. (security.paloaltonetworks.com)
The inclusion of CVE-2026-0257 in the KEV Catalog underscores the ongoing threat posed by authentication bypass vulnerabilities in widely used network security products. As attackers continue to exploit such flaws, it is imperative for organizations to maintain vigilant patch management practices and monitor for emerging threats to safeguard their networks.
Why This Matters Now
The addition of CVE-2026-0257 to CISA's KEV Catalog highlights the immediate need for organizations to address authentication bypass vulnerabilities in their network security infrastructure. Prompt remediation is crucial to prevent unauthorized access and potential data breaches.
Attack Path Analysis
An attacker exploited an authentication bypass vulnerability in the GlobalProtect portal of Palo Alto Networks PAN-OS to establish an unauthorized VPN connection. This allowed the attacker to escalate privileges by accessing internal systems with elevated rights. Subsequently, the attacker moved laterally within the network to identify and access sensitive resources. They established command and control channels to maintain persistent access and exfiltrated sensitive data. Finally, the attacker disrupted operations by deploying ransomware, encrypting critical data, and demanding a ransom.
Kill Chain Progression
Initial Compromise
Description
Exploited an authentication bypass vulnerability in the GlobalProtect portal to establish an unauthorized VPN connection.
Related CVEs
CVE-2026-0257
CVSS 9.1Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS software allow attackers to establish unauthorized VPN connections.
Affected Products:
Palo Alto Networks PAN-OS – < 12.1.4-h6, < 12.1.7, < 11.2.4-h17, < 11.2.7-h14, < 11.2.10-h7, < 11.2.12, < 11.1.4-h33, < 11.1.6-h32, < 11.1.7-h6, < 11.1.10-h25, < 11.1.13-h5, < 11.1.15, < 10.2.7-h34, < 10.2.10-h36, < 10.2.13-h21, < 10.2.16-h7, < 10.2.18-h6
Palo Alto Networks Prisma Access – < 11.2.7-h13, < 10.2.10-h36
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Valid Accounts
External Remote Services
Application Layer Protocol
Remote Services
Network Sniffing
Cloud Accounts
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Authentication for Remote Access
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Encryption of Nonpublic Information
Control ID: 500.15
DORA – ICT Risk Management Framework
Control ID: Article 6
CISA ZTMM 2.0 – Identity Governance
Control ID: Pillar 1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Federal agencies face critical authentication bypass vulnerabilities in Palo Alto Networks PAN-OS systems, requiring immediate remediation under BOD 22-01 compliance mandates.
Financial Services
Banking institutions using PAN-OS firewalls risk authentication bypass exploitation, threatening encrypted traffic protection and compliance with PCI DSS requirements.
Health Care / Life Sciences
Healthcare organizations face HIPAA compliance violations and patient data exposure through PAN-OS authentication bypass vulnerabilities in network security infrastructure.
Computer/Network Security
Cybersecurity providers must address authentication bypass vulnerabilities in PAN-OS deployments while maintaining zero trust segmentation and threat detection capabilities.
Sources
- CISA Adds One Known Exploited Vulnerability to Cataloghttps://www.cisa.gov/news-events/alerts/2026/05/29/cisa-adds-one-known-exploited-vulnerability-catalogVerified
- PAN-OS: GlobalProtect Authentication Bypass Vulnerabilitieshttps://security.paloaltonetworks.com/CVE-2026-0257Verified
- NVD - CVE-2026-0257https://nvd.nist.gov/vuln/detail/CVE-2026-0257Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have significantly limited the attacker's ability to move laterally, escalate privileges, and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's unauthorized VPN connection would likely have been constrained, reducing their ability to access internal systems.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges would likely have been limited, reducing their access to sensitive systems.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement would likely have been constrained, limiting their ability to access additional systems.
Control: Multicloud Visibility & Control
Mitigation: The attacker's command and control channels would likely have been detected and disrupted, reducing their ability to maintain access.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts would likely have been restricted, limiting the amount of data removed.
The attacker's ability to deploy ransomware would likely have been constrained, reducing the scope of data encryption.
Impact at a Glance
Affected Business Functions
- Remote Access VPN
- Network Security
- User Authentication
Estimated downtime: 3 days
Estimated loss: $50,000
Potential unauthorized access to internal network resources and sensitive data.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and prevent unauthorized lateral movement.
- • Deploy East-West Traffic Security controls to monitor and restrict internal traffic, mitigating lateral movement.
- • Utilize Egress Security & Policy Enforcement to control outbound traffic and prevent data exfiltration.
- • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to suspicious activities promptly.
- • Regularly update and patch systems to address known vulnerabilities and reduce the attack surface.



