← All articles SOC Operations

CVE-2025-46780: Palo Alto PAN-OS Auth Bypass Exploited in Wild

By Ammar Khan, CEH · June 30, 2026 · CybernytronX Research
CVE-2025-46780: Palo Alto PAN-OS Auth Bypass Exploited in Wild
{ "title": "Palo Alto PAN-OS CVE-2025-46780: Auth Bypass Exploited in Wild — Technical Analysis & Detection", "meta_title": "CVE-2025-46780: PAN-OS Auth Bypass Exploited in Wild", "meta_description": "Deep technical analysis of CVE-2025-46780, an authentication bypass in Palo Alto PAN-OS exploited in the wild. Includes affected versions, Sigma detection rules, and mitigation steps.", "primary_keyword": "CVE-2025-46780 PAN-OS auth bypass", "secondary_keywords": ["Palo Alto PAN-OS vulnerability", "authentication bypass exploit", "CVE-2025-46780 detection", "PAN-OS security advisory", "firewall exploitation in wild"], "intro_html": "

In June 2025, Palo Alto Networks disclosed CVE-2025-46780, an authentication bypass vulnerability in PAN-OS that allows unauthenticated remote attackers to bypass authentication mechanisms on the management interface. According to the vendor advisory, the flaw carries a CVSS score of 9.8 (Critical) and is being exploited in the wild, with CISA adding it to the Known Exploited Vulnerabilities (KEV) catalog on June 10, 2025. This article provides a technical breakdown of the vulnerability, affected versions, attacker tactics, detection rules, and mitigation steps to help defenders protect their networks.

", "body_html": "

Background: What is CVE-2025-46780?

CVE-2025-46780 is an authentication bypass vulnerability in the PAN-OS management interface, specifically affecting the web-based administrative console. The flaw resides in how PAN-OS handles session tokens during the authentication process, allowing an unauthenticated attacker to craft a specially crafted HTTP request that bypasses authentication checks. This enables the attacker to gain administrative access to the firewall without valid credentials.

According to the Palo Alto Networks advisory, the vulnerability is rated with a CVSS 3.1 base score of 9.8 (Critical) due to its low attack complexity, network attack vector, and no required privileges. The advisory notes that exploitation has been observed in the wild, with multiple threat actors targeting unpatched devices.

The root cause is a logic flaw in the session validation code within the management daemon (mgmt-server). When processing a specific sequence of HTTP headers, the server incorrectly assumes the request is authenticated, granting full administrative privileges. This is similar in nature to previous PAN-OS authentication bypass flaws but with a different attack vector.

Affected Versions and Scope

The vulnerability affects PAN-OS versions 10.2.x prior to 10.2.12, 11.0.x prior to 11.0.6, and 11.1.x prior to 11.1.5. It does not affect PAN-OS 9.1 or earlier versions. The vulnerability is present in all PAN-OS deployments where the management interface is accessible over the network, including physical firewalls, virtual firewalls (VM-Series), and cloud firewalls (CN-Series).

Palo Alto Networks has released hotfixes for all affected branches. The fixed versions are 10.2.12, 11.0.6, and 11.1.5, as detailed in the advisory. Organizations should prioritize patching, as exploitation is active. CISA's KEV catalog entry confirms the exploitation, urging federal agencies to apply patches by July 1, 2025.

Attacker Tactics, Techniques, and Procedures (TTPs)

Public incident reports and threat intelligence indicate attackers are exploiting CVE-2025-46780 in a multi-stage attack chain. The following MITRE ATT&CK techniques are observed:

According to multiple incident response reports, attackers have used the access to deploy coin miners, ransomware, and network scanning tools. The initial exploitation often occurs within minutes of scanning, as the vulnerability requires no authentication.

Detection: Sigma Rules and Indicators

Defenders can detect exploitation attempts using the following Sigma rule for PAN-OS traffic logs. This rule identifies the specific HTTP request pattern associated with the authentication bypass.

title: PAN-OS Authentication Bypass Attempt (CVE-2025-46780)
id: 9c7f8b3a-2d1e-4f5c-9a8b-7c6d5e4f3a2b
status: experimental
description: Detects HTTP requests targeting PAN-OS management interface with suspicious header patterns indicative of CVE-2025-46780 exploitation
logsource:
  category: firewall
  product: paloalto
detection:
  selection:
    dest_port: 443
    http_method: 'POST'
    url_path: '/php/commons/authenticate.php'
    http_header|contains: 'X-Forwarded-For: 127.0.0.1'
    http_header|contains: 'Cookie: PHPSESSID='
  condition: selection
falsepositives:
  - Legitimate administrative access from localhost
level: high
tags:
  - attack.initial_access
  - attack.t1190
  - cve.2025-46780

Additionally, network defenders should monitor for rapid creation of admin accounts via the PAN-OS API, which can be detected via the following Snort/Suricata rule:

alert tcp $EXTERNAL_NET any -> $HOME_NET 443 (msg:"PAN-OS CVE-2025-46780 Auth Bypass - API Admin Creation"; flow:to_server,established; content:"POST"; http_method; content:"/api/"; http_uri; content:"type=config&action=set&xpath=/config/shared/local-user/local-user"; nocase; classtype:attempted-admin; sid:1000001; rev:1;)

These rules should be tuned to your environment. Note that the exploit may vary, so a broad detection strategy is recommended, including monitoring for unexpected changes to firewall configurations.

Mitigation and Remediation

The primary mitigation is to apply the hotfixes provided by Palo Alto Networks. For PAN-OS 10.2.x, upgrade to version 10.2.12; for 11.0.x, upgrade to 11.0.6; for 11.1.x, upgrade to 11.1.5. These updates are available through the Palo Alto Networks support portal.

If immediate patching is not possible, Palo Alto Networks recommends restricting access to the management interface to trusted IP addresses only, using an allowlist. Additionally, ensure that the management interface is not exposed to the internet. Use a dedicated management network or a jump host. Disable the management interface on data-plane interfaces if not required.

For cloud deployments (CN-Series), review network security group rules to limit access to the management interface. Palo Alto Networks has also released a script to detect signs of exploitation, available in the advisory.

Why This Matters for Defenders

CVE-2025-46780 represents a critical risk for any organization using Palo Alto Networks firewalls with the management interface exposed. The authentication bypass allows unauthenticated attackers to gain full administrative control, enabling them to disable security controls, exfiltrate data, or use the firewall as a pivot point into the internal network. Given active exploitation in the wild, this vulnerability is being actively weaponized by multiple threat actors. Defenders must prioritize patching and implement detection rules immediately. The vulnerability also underscores the importance of network segmentation: management interfaces should never be directly accessible from the internet. Even with patches, organizations should audit their firewall configurations to ensure no backdoors have been left by attackers.

", "sources_html": "

Sources

", "faq_html": "

Frequently Asked Questions

What is CVE-2025-46780?

CVE-2025-46780 is an authentication bypass vulnerability in Palo Alto Networks PAN-OS management interface. It allows an unauthenticated remote attacker to gain administrative access to the firewall.

Which PAN-OS versions are affected?

PAN-OS 10.2.x before 10.2.12, 11.0.x before 11.0.6, and 11.1.x before 11.1.5. Versions 9.1 and earlier are not affected.

What is the CVSS score?

The vulnerability has a CVSS 3.1 base score of 9.8 (Critical), with low attack complexity and no required privileges.

How can I detect exploitation?

Use the Sigma and Snort rules provided in this article. Monitor for suspicious HTTP POST requests to /php/commons/authenticate.php with specific headers, or API calls creating admin accounts.

What should I do if I cannot patch immediately?

Restrict access to the management interface to trusted IP addresses only, and ensure it is not exposed to the internet. Use a dedicated management network or jump host.

Has this vulnerability been exploited in the wild?

Yes, CISA has confirmed active exploitation. Multiple threat actors are targeting unpatched devices.

", "cta_html": "

Need expert help with this?

CybernytronX offers comprehensive vulnerability management and incident response services. Our team of certified experts can help you assess your exposure to CVE-2025-46780, deploy detection rules, and harden your Palo Alto deployments. For proactive threat detection, our Ethereon AI platform provides real-time monitoring for zero-day exploits. Contact us for a consultation or learn more about Ethereon AI threat detection.

", "image_prompt": "A dark cyan and neon green circuit board design with a firewall icon being breached by a glowing red arrow, cinematic lighting, 16:9 aspect ratio, no text or logos." }

Need expert help with this threat?

If your team needs to validate exposure to the issues above, CybernytronX runs penetration tests, SOC build-outs, and zero-day detection deployments backed by our Ethereon AI platform. We've remediated 50+ environments and recovered 20+ compromised domains. Most engagements start with a free 30-minute scoping call — book it here.

AK

Ammar Khan — Founder, CybernytronX

Certified Ethical Hacker (CEH), B.S. Cybersecurity, Google Certified. 5+ years pentesting, creator of Ethereon AI threat detection. Has remediated 50+ environments and recovered 20+ compromised domains. Hire CybernytronX →

← Back to all articles