Article

    Cyber News / Article / A Vulnerability in PAN-OS Could Allow for Authentication Bypass

    A Vulnerability in PAN-OS Could Allow for Authentication Bypass
    -2026-06-22

    A Vulnerability in PAN-OS Could Allow for Authentication Bypass

    A vulnerability has been discovered in the GlobalProtect portal and gateway of PAN-OS which could allow for authentication bypass. The PAN-OS GlobalProtect Portal acts as the central control plane for Palo Alto Networks VPN infrastructure. Successful exploitation of the vulnerability allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.

    Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied.CISA also added the vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

    A vulnerability has been discovered in the GlobalProtect portal and gateway of PAN-OS which could allow for authentication bypass. Details of the vulnerability are as follows:

    Tactic:Initial Access(TA0001):

    Technique:Exploit Public-Facing Application(T1190):

    Successful exploitation of the vulnerability allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. An attacker may then be able to execute scripts, install programs; view, change, or delete data, conduct network reconnaissance, lateral movement, or data exfiltration.

    We recommend the following actions be taken:

    Copyright©2026 Center for Internet Security®

    Original source