🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.

Palo Alto Networks PAN-OS Authentication Bypass VPN (CVE-2026-0257) | MSSP Advisory

Critical🔴 KEV ALERTConfirmed
DateMay 29, 2026
CVECVE-2026-0257
Risk Assessment
Client Exposure:High
Briefing Priority:Immediate
Barrier to Entry:Low
📋Executive Summary
CISA flagged CVE-2026-0257, an authentication bypass flaw in Palo Alto Networks PAN-OS that lets attackers establish unauthorized VPN connections without valid credentials. This is already on the Known Exploited Vulnerabilities catalog, meaning active exploitation is happening now.
⚠️Why It Matters for MSSPs
Your MSSP infrastructure likely runs on Palo Alto firewalls for remote access and client network protection, making you a direct target for credential theft and lateral movement. Every client with Palo Alto devices faces immediate compromise risk, and failing to alert them creates a retention and liability exposure.
Recommended Action
Audit your entire Palo Alto estate within 24 hours and apply vendor patches immediately where available. Contact all clients with PAN-OS devices and provide emergency patching guidance or temporary mitigation steps before end of business today.
🔒
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
Get your first advisory free →
🏷️Threat Category
Zero-Day

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.