tag
Palo-Alto
CVE-2026-0257
web
HIGH 7.8
KEV
Ransomware
EPSS 94%
PAN-OS GlobalProtect Authentication Bypass via Forged Cookie (CVE-2026-0257)
CVE-2026-0257 is an authentication bypass in the GlobalProtect portal and gateway components of PAN-OS. In configurations where the same TLS certificate is reused for both the HTTPS service and the authentication-override cookie's encryption/decryption, an…
Unverified
2026-07-01
CVE-2025-0108
web
CRITICAL 9.1
KEV
EPSS 98%
Palo Alto PAN-OS Management Interface Authentication Bypass (CVE-2025-0108)
CVE-2025-0108 is an authentication bypass in the PAN-OS management interface that can allow unauthorized administrative access. The PoC uses a crafted path traversal style request to reach sensitive management functionality without a valid login session.…
Patched
2026-05-16