CVE-2026-0257: Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

Added to the CISA Known Exploited Vulnerabilities catalog on 29 May 2026. Vendor: Palo Alto Networks. Product: PAN-OS.

Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. (due 01 Jun 2026)