T The Triage ManualTechnical Guides for IT Emergencies
P1 · Network Infrastructure

CVE-2026-0265: PAN-OS Authentication Bypass via Cloud Authentication Service Signature Verification Flaw

CVE-2026-0265 is a signature verification vulnerability in PAN-OS that allows unauthenticated remote attackers to bypass authentication when Cloud Authentication Service (CAS) is enabled on a login interface. Exploitation has been confirmed against GlobalProtect portals establishing unauthorized VPN sessions. Affected platforms include PA-Series, VM-Series firewalls and Panorama appliances running vulnerable PAN-OS versions. Emergency patching is required — workarounds are insufficient due to disputed severity between vendor (CVSS 7.2) and researcher claims of active exploitation.

Indicators

Likely causes

Diagnostic steps

  1. Check the running PAN-OS version on each firewall or Panorama appliance via CLI: `show system info | match version` — or via management UI: Dashboard > General Information
    Determine whether the device is running a vulnerable PAN-OS version as listed in the advisory
  2. Verify CAS configuration: Navigate to Device > Authentication Profile and check for CAS-backed profiles assigned to login interfaces. Follow official Palo Alto Networks advisory instructions for detailed verification steps.
    Confirm whether the vulnerable configuration (CAS enabled on a login interface) is present — if CAS is not attached to a login interface, the device is not exploitable via this CVE
  3. Identify all internet-facing login interfaces: enumerate management interfaces, GlobalProtect portals, and GlobalProtect gateways that have CAS-backed authentication profiles attached. Assess network exposure of each.
    Prioritize highest-risk interfaces — unrestricted internet-facing management interfaces with CAS are highest risk; GlobalProtect portals with CAS are also exploitable per researcher findings
  4. Cross-reference running PAN-OS version against fixed version table: PAN-OS 12.1 >= 12.1.7 (ETA 05/28); PAN-OS 11.2 >= 11.2.7-h13, >= 11.2.10-h6, >= 11.2.12 (ETA 05/28); PAN-OS 11.1 >= 11.1.6-h32, >= 11.1.10-h25, >= 11.1.13-h5; PAN-OS 10.2 >= 10.2.10-h36, >= 10.2.18-h6
    Determine which devices require immediate patching versus which must wait for patches expected May 28, 2026
  5. Review authentication and access logs on affected appliances for anomalous or unauthenticated login events on CAS-enabled interfaces, particularly management interfaces and GlobalProtect portals.
    Determine whether exploitation may have already occurred prior to patching — identify potential indicators of compromise
  6. Scan environment using Rapid7 Exposure Command, InsightVM, or Nexpose for CVE-2026-0265 exposure.
    Obtain automated inventory of vulnerable PAN-OS assets for prioritization and tracking remediation progress

Resolution path

Prevention

Tools

References

CVE-2026-0265Palo Alto NetworksPAN-OSauthentication bypasssignature verificationCloud Authentication ServiceCASGlobalProtectfirewallPanoramaPA-SeriesVM-Seriesunauthenticated remote accessVPNnetwork securitypatch managementCVSS Highemergency patching2026