PAN-OS GlobalProtect authentication bypass
PAN-OS GlobalProtect portal and gateway authentication bypass allowing an unauthorized VPN connection under a specific authentication-override-cookie and certificate configuration. Actively exploited by Qilin ransomware.
- Vendor
- Palo Alto Networks
- Product
- PAN-OS (GlobalProtect portal and gateway)
- CVSS
- 9.1
- EPSS (exploit probability)
- N/A
- Status
- kev
- Published
An authentication-bypass flaw in the PAN-OS GlobalProtect portal and gateway. Under a specific configuration — authentication override cookies enabled alongside a particular certificate setup, per Palo Alto Networks’ advisory — an unauthenticated attacker can establish an unauthorized VPN connection.
Affected and fixed builds, per the vendor:
- PAN-OS 12.1: patched in 12.1.7
- PAN-OS 11.2: patched in 11.2.12
- PAN-OS 11.1: patched in 11.1.15
- PAN-OS 10.2: patched in 10.2.18-h6
Cloud NGFW and Panorama are not affected. Prisma Access received corresponding patches; see the advisory for cloud-side build levels.
Scoring note. Palo Alto Networks scores this 7.8 (High) under CVSS 4.0. NVD scores it 9.1 (Critical) under CVSS 3.1. The disagreement is between scoring systems, not between findings — the flaw is the same in both.
Exploitation. Rapid7 first reported exploitation on May 17, 2026, four days after the patch. CISA added the CVE to its Known Exploited Vulnerabilities catalog on May 29, 2026, with a three-day patch deadline for federal civilian agencies. Arctic Wolf Labs documented multiple Qilin ransomware intrusions in June that traced back to unpatched GlobalProtect portals, and assessed with moderate confidence that exploitation is ongoing based on continued scanning activity — reporting via BleepingComputer, 2026-07-21.
Shadowserver tracks over 167,000 GlobalProtect instances exposed to the internet; patch status on the majority is not knowable from the outside.
See the 0dayNews writeup: Qilin exploits PAN-OS GlobalProtect CVE-2026-0257.
