Ridge Security Palo Alto Networks GlobalProtect Authentication Bypass: What Security Teams Should Know About CVE-2026-0257Award
Palo Alto Networks GlobalProtect Authentication Bypass: What Security Teams Should Know About CVE-2026-0257
Palo Alto Networks GlobalProtect is widely used by enterprises to provide secure remote access to internal systems and applications. Because VPN gateways often sit at the edge of corporate networks, vulnerabilities in these systems can quickly become high-priority risks for security teams.
On May 13, 2026, Palo Alto Networks disclosed CVE-2026-0257, an authentication bypass vulnerability affecting the GlobalProtect portal and gateway components of PAN-OS and certain Prisma Access deployments. The vulnerability allows a remote, unauthenticated attacker to bypass GlobalProtect authentication and establish an unauthorised VPN connection when specific configuration conditions are present.

