Improper Verification of Cryptographic Signature in Palo Alto PAN-OS - CVE-2026-0265
Published: May 19, 2026 / Updated: August 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication controls.
The vulnerability exists due to improper verification of cryptographic signature in the Cloud Authentication Service (CAS) authentication mechanism when handling authentication requests on a login interface with CAS enabled. A remote attacker can send a crafted authentication request to bypass authentication controls.
The risk is higher when CAS is enabled on the management interface.
Affected software
How to mitigate CVE-2026-0265
Links to Public Exploits and PoC-codes
- Exploit #12977 - PAN-OS GlobalProtect CAS CVE-2026-0265 Vulnerability Checker (August 26, 2026)
- Exploit #12741 - palo-alto-cve-2026-0265-checker (Python script to sweep a fleet of Palo Alto firewalls and Panoramas via SSH, check PAN-OS version against CVE-2026-0265 (Authentication Bypass via Cloud Authentication Service), detect whether CAS is actually configured, a (May 22, 2026)