Skip to main content
kcheung
Staff
Staff
July 13, 2026

FortiGuard Outbreak Alert: Palo Alto Networks PAN-OS GlobalProtect Auth Bypass

  • July 13, 2026
  • 0 replies
  • 34 views

Description

Palo Alto Networks PAN-OS GlobalProtect is a secure remote-access VPN solution integrated with PAN-OS firewalls that provides users with authenticated, encrypted access to corporate networks and applications from anywhere.

Attackers are actively exploiting PAN-OS GlobalProtect authentication bypass vulnerability to gain unauthorized VPN access to exposed Palo Alto Networks firewalls.

CVE-2026-0257 is an authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect which allows unauthenticated attackers to bypass security restrictions and establish unauthorized VPN connections.

For affected and fixed product versions, refer to the Palo-Alto security advisory links below:

CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities

CVE ID

CVE-2026-0257

NDR Cloud Detection Rule

FortiNDR Cloud v26.2b+

Detection Rule Name

Category

Primary MITRE ID

FortiGuard Outbreak Alert: Palo Alto Networks PAN-OS GlobalProtect Authentication Bypass - CVE-2026-0257

Attack: Exploitation

T1190 - Exploit Public-Facing Application

Playbook

N/A

Threat Hunting

FortiNDR Cloud users can use the following IOCs from Fortinet to hunt for 'Palo Alto Networks PAN-OS GlobalProtect Auth Bypass' related activities.


IOC source: Palo Alto Networks PAN-OS GlobalProtect Auth Bypass | Indicators of Compromise.


All IOCs relating to 'Palo Alto Networks PAN-OS GlobalProtect Auth Bypass' have been added to Threat Intelligence Intel.

Suricata/DPI Coverage

Customers can create custom investigation/detections using the DPI and Suricata signatures below:

DPI:

DPI Vulnerability ID (dpi_vuln_id)

DPI Alert Signature

61037

Palo.Alto.Networks.GlobalProtect.Authentication.Bypass

Suricata:

Suricata Signature ID

Suricata Signature

100109432

ATR EXPLOITATION Palo Alto Networks PAN-OS GlobalProtect Authentication Bypass - CVE-2026-0257

Other Fortinet Products

For more details regarding mitigating the vulnerability by utilizing Fortinet products, refer to Palo Alto Networks PAN-OS GlobalProtect Auth Bypass.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!