Skip to content
eastbaycyber

CISA Adds 1 Known Exploited Vulnerability to Catalog (May 29, 2026)

Source: CISA KEV Catalog · Updated 2026-09-25

Summary

On May 29, 2026, CISA added 1 vulnerability to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-0257. A KEV listing means CISA has evidence of active exploitation. CISA sets a remediation due date for US federal civilian agencies under its binding operational directives; any organization running the affected products should treat these as patch-now priorities.

CVE-2026-0257: Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

Palo Alto Networks · PAN-OS

Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.

Federal due date
2026-06-01
Ransomware use
Known
Added
2026-05-29

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

NVD record · Palo Alto Networks KEV history

Check whether you run these products: our vulnerability scanner comparison covers tools that detect KEV-listed flaws. See also the KEV dashboard and KEV history by vendor.