Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryidentity-authentication-vulnerabilityperimeter-device-exposureproof-of-concept-release

Palo Alto PAN-OS Authentication Bypass Exposes CAS-Enabled Firewalls and Panorama

Updated 29d agoFirst seen May 13, 20266 sources

Palo Alto Networks released security advisories for multiple PAN-OS branches after disclosing several serious flaws, including CVE-2026-0265, an authentication bypass caused by a signature verification weakness when Cloud Authentication Service (CAS) is enabled and attached to a login interface. The issue affects PA-Series, VM-Series, and Panorama deployments, while Cloud NGFW and Prisma Access are not affected. Palo Alto also warned of a heap-based buffer overflow in the DNS Proxy and DNS Server that could enable unauthenticated remote code execution, as well as a separate remote code execution flaw in IKEv2 processing across supported releases including 12.1, 11.2, 11.1, and 10.2.

The Canadian Centre for Cyber Security urged administrators to review Palo Alto’s advisories, apply mitigations, and install updates, with fixes already issued for many affected versions and additional patches expected for some branches. Rapid7 said organizations using CAS should prioritize emergency patching rather than depend on workarounds, while researcher Harsh Jaiswal of HacktronAI publicly claimed successful exploitation of the authentication bypass against multiple companies’ GlobalProtect portals to obtain VPN access; Palo Alto had not confirmed in-the-wild exploitation as of May 14.

Share:
Palo Alto PAN-OS Authentication Bypass Exposes CAS-Enabled Firewalls and Panorama
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
May 22, 20261mo ago

Bishop Fox publishes CVE-2026-0265 detection method and technical analysis

On 2026-05-22, Bishop Fox published technical analysis of CVE-2026-0265, describing it as a JWT signature bypass tied to algorithm confusion in pan_auth_verify that can affect GlobalProtect portals and PAN-OS management interfaces when CAS is enabled. The firm also released a detection method and script that use an anonymous GlobalProtect prelogin request to identify CAS exposure and determine whether a target is running a vulnerable version.

Detecting CVE-2026-0265 at Scale: PAN-OS CAS… | Bishop Fox

JPCERT/CC warns Japan-based organizations about CVE-2026-0265

On 2026-05-22, JPCERT/CC published advisory JPCERT-AT-2026-0015 warning that PAN-OS systems with Cloud Authentication Service enabled could be remotely compromised via authentication bypass. The advisory cited public technical analysis showing GlobalProtect VPN access could be obtained, warned exploit code may emerge and attacks could spread in Japan, and urged immediate patching or vendor mitigations.

Palo Alto Networks製PAN-OSにおける認証回避の脆弱性(CVE-2026-0265)に関する注意喚起
May 14, 20261mo ago

HacktronAI reports successful exploitation of CVE-2026-0265

By 2026-05-14, researcher Harsh Jaiswal of HacktronAI said the firm had successfully exploited CVE-2026-0265 against multiple corporations' GlobalProtect portals to obtain VPN access. Palo Alto had not confirmed in-the-wild exploitation at that time, and HacktronAI said fuller technical details would be released during the week of 2026-05-18.

May 13, 20261mo ago

Canadian Centre for Cyber Security urges immediate mitigation

On 2026-05-13, the Canadian Centre for Cyber Security published advisory AV26-462 summarizing the Palo Alto Networks disclosures and urging administrators to review the vendor advisories, apply mitigations, and install updates. The notice highlighted the authentication bypass, DNS-related remote code execution risk, and IKEv2 processing flaw.

Palo Alto Networks releases patches for many affected PAN-OS versions

Alongside the advisories on 2026-05-13, Palo Alto Networks issued fixes for many impacted PAN-OS version streams, including affected 12.1, 11.2, 11.1, and 10.2 releases. Additional fixes for some remaining affected versions were scheduled for release on 2026-05-28.

Palo Alto Networks discloses CVE-2026-0265 and related PAN-OS flaws

On 2026-05-13, Palo Alto Networks published security advisories for multiple PAN-OS branches, including CVE-2026-0265, an authentication bypass affecting deployments using Cloud Authentication Service (CAS). The advisories also covered other serious issues, including a heap-based buffer overflow in DNS components and an IKEv2 remote code execution flaw.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

16 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.