high
CVE-2026-0257
PAN-OS GlobalProtect authentication bypass - an attacker establishes VPN connections without valid credentials
- Severity
- high
- Affected product
- PaloAlto GlobalProtect
- Affected versions
- PaloAlto GlobalProtect all versions before the fix
- Added to NewScan
- 2026-08-06
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the PaloAlto GlobalProtect appliance and reports this CVE when the detected version falls inside the affected range below.
Rapid7 observed successful exploitation from 2026-05-17, second wave 2026-05-21. Advisory: PAN-OS does not publish its version on the portal anonymously.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →