PoC Archive PoC Archive

tag

PAN-OS

  • CVE-2026-0257 web HIGH 7.8 KEV Ransomware EPSS 94%

    PAN-OS GlobalProtect Authentication Bypass via Forged Cookie (CVE-2026-0257)

    CVE-2026-0257 is an authentication bypass in the GlobalProtect portal and gateway components of PAN-OS. In configurations where the same TLS certificate is reused for both the HTTPS service and the authentication-override cookie's encryption/decryption, an…

    Unverified 2026-07-01
  • CVE-2024-3400 web CRITICAL 10 KEV Ransomware EPSS 100%

    Palo Alto PAN-OS GlobalProtect Unauthenticated RCE (CVE-2024-3400)

    CVE-2024-3400 is an unauthenticated command injection vulnerability in PAN-OS GlobalProtect that can be reached over the network when specific features are enabled. Public reporting showed chained abuse via arbitrary file creation and command execution as…

    Patched 2026-05-17
  • CVE-2025-0108 web CRITICAL 9.1 KEV EPSS 98%

    Palo Alto PAN-OS Management Interface Authentication Bypass (CVE-2025-0108)

    CVE-2025-0108 is an authentication bypass in the PAN-OS management interface that can allow unauthorized administrative access. The PoC uses a crafted path traversal style request to reach sensitive management functionality without a valid login session.…

    Patched 2026-05-16