Palo Alto Networks released security advisories for multiple PAN-OS branches after disclosing several serious flaws, including CVE-2026-0265, an authentication bypass caused by a signature verification weakness when Cloud Authentication Service (CAS) is enabled and attached to a login interface. The issue affects PA-Series, VM-Series, and Panorama deployments, while Cloud NGFW and Prisma Access are not affected. Palo Alto also warned of a heap-based buffer overflow in the DNS Proxy and DNS Server that could enable unauthenticated remote code execution, as well as a separate remote code execution flaw in IKEv2 processing across supported releases including 12.1, 11.2, 11.1, and 10.2.
The Canadian Centre for Cyber Security urged administrators to review Palo Alto’s advisories, apply mitigations, and install updates, with fixes already issued for many affected versions and additional patches expected for some branches. Rapid7 said organizations using CAS should prioritize emergency patching rather than depend on workarounds, while researcher Harsh Jaiswal of HacktronAI publicly claimed successful exploitation of the authentication bypass against multiple companies’ GlobalProtect portals to obtain VPN access; Palo Alto had not confirmed in-the-wild exploitation as of May 14.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-22, Bishop Fox published technical analysis of CVE-2026-0265, describing it as a JWT signature bypass tied to algorithm confusion in pan_auth_verify that can affect GlobalProtect portals and PAN-OS management interfaces when CAS is enabled. The firm also released a detection method and script that use an anonymous GlobalProtect prelogin request to identify CAS exposure and determine whether a target is running a vulnerable version.
On 2026-05-22, JPCERT/CC published advisory JPCERT-AT-2026-0015 warning that PAN-OS systems with Cloud Authentication Service enabled could be remotely compromised via authentication bypass. The advisory cited public technical analysis showing GlobalProtect VPN access could be obtained, warned exploit code may emerge and attacks could spread in Japan, and urged immediate patching or vendor mitigations.
By 2026-05-14, researcher Harsh Jaiswal of HacktronAI said the firm had successfully exploited CVE-2026-0265 against multiple corporations' GlobalProtect portals to obtain VPN access. Palo Alto had not confirmed in-the-wild exploitation at that time, and HacktronAI said fuller technical details would be released during the week of 2026-05-18.
On 2026-05-13, the Canadian Centre for Cyber Security published advisory AV26-462 summarizing the Palo Alto Networks disclosures and urging administrators to review the vendor advisories, apply mitigations, and install updates. The notice highlighted the authentication bypass, DNS-related remote code execution risk, and IKEv2 processing flaw.
Alongside the advisories on 2026-05-13, Palo Alto Networks issued fixes for many impacted PAN-OS version streams, including affected 12.1, 11.2, 11.1, and 10.2 releases. Additional fixes for some remaining affected versions were scheduled for release on 2026-05-28.
On 2026-05-13, Palo Alto Networks published security advisories for multiple PAN-OS branches, including CVE-2026-0265, an authentication bypass affecting deployments using Cloud Authentication Service (CAS). The advisories also covered other serious issues, including a heap-based buffer overflow in DNS components and an IKEv2 remote code execution flaw.
According to HacktronAI's write-up, the researcher notified Palo Alto Networks about CVE-2026-0265 on 2026-03-26 after validating an authentication bypass affecting PAN-OS GlobalProtect deployments using Cloud Authentication Service. The vendor later triaged the issue on 2026-04-08.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
8 references tracked. Mallory keeps watching after this page renders.
jpcert.or.jp
Open sourcebishopfox.com
Open sourcegithub.com
Open sourcehacktron.ai
Open sourceccb.belgium.be
Open sourcerapid7.com
Open sourcecyber.gc.ca
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.