CVE-2026-0257
CRITICAL KEV NUCLEIPAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
Title source: cnaExploitation Summary
CVE-2026-0257 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added May 29, 2026. EIP tracks 9 public exploits from researchers including grayxploit, tushargurav28, sfewer-r7. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository contains a scanner for CVE-2026-0257, which targets PAN-OS GlobalProtect authentication bypass vulnerabilities. The tool detects vulnerable instances by forging authentication override cookies and testing them against GlobalProtect endpoints.
Description
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.
Exploits (9)
This repository contains a scanner for CVE-2026-0257, which targets PAN-OS GlobalProtect authentication bypass vulnerabilities. The tool detects vulnerable instances by forging authentication override cookies and testing them against GlobalProtect endpoints.
This repository contains a functional exploit for CVE-2026-0257, a critical authentication bypass vulnerability in Palo Alto GlobalProtect VPN. The exploit forges a valid authentication cookie using the server's public RSA key extracted from its TLS certificate, allowing unauthenticated VPN access.
This repository contains a functional exploit PoC for CVE-2026-0257, which demonstrates an authentication bypass vulnerability in Palo Alto Networks GlobalProtect. The script forges a valid authentication override cookie using the public key from the TLS certificate chain and tests it against the target GlobalProtect portal or gateway.
The repository claims to provide an exploit for CVE-2026-0257, an authentication bypass in Palo Alto Networks GlobalProtect portal, but lacks actual exploit code. Instead, it directs users to an external download link (tinyurl.com), which is a common tactic for distributing malware or monetizing fake exploits.
This repository contains a functional exploit PoC for CVE-2026-0257, which allows unauthenticated attackers to forge GlobalProtect authentication override cookies by extracting public keys from the TLS certificate chain and testing them against the target's login endpoint.
The repository claims to provide an exploit for CVE-2026-0257, an authentication bypass in Palo Alto Networks GlobalProtect portal, but contains no actual exploit code. Instead, it directs users to an external download link (tinyurl.com), which is a common tactic for distributing malware or monetizing fake exploits.
This repository provides a detailed technical analysis of CVE-2026-0257, an authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect. It includes severity scoring, affected versions, exploitation status, and mitigation strategies, but does not contain functional exploit code.
The repository contains only placeholder files (README.md, LICENSE, .gitignore, and a template file) with no actual exploit code or technical details about CVE-2026-0257. The README is a generic template with no specific information about the vulnerability or exploit.
This repository contains a Python-based scanner for detecting CVE-2026-0257, an authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect. The script performs passive, read-only checks to identify vulnerable versions and behavioral indicators without attempting exploitation.
Nuclei Templates (1)
http.title:"GlobalProtect" port:443
title="GlobalProtect"
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N