Firewall Vendor Zero-Days of 2026
Six actively-exploited zero-days across Palo Alto Networks, Fortinet, Check Point and Cisco — and the single failure pattern they all share.
5 pages • ~9 min read • Published July 2026
Download the PDF Request a proof of concept →The short version
Over the past several months, four of the industry’s best-known perimeter security vendors each disclosed critical, actively-exploited zero-day vulnerabilities in their firewall, VPN or SD-WAN products. Several carry CVSS scores above 9.0. Several were exploited before a patch existed. At least two are tied to known ransomware operations, and in one case CISA gave federal agencies a three-day emergency patch window. The pattern is consistent: the firewall or VPN appliance is the trust boundary and the single point of enforcement, so a flaw in its authentication or management logic does not just create a hole — it hands the attacker the keys to everything the device was supposed to protect.
A note on how to read this
These are commentary and analysis, not independent test results. Each incident is summarized from public reporting and vendor advisories, followed by how PacketViper’s stated architecture — an inline, agentless, preemptive layer that sits alongside, not in place of, the firewall — is positioned to address that category of exposure. Where PacketViper has not been validated against a specific CVE, that is noted rather than implied.
The six incidents
1. Palo Alto Networks PAN-OS — unauthenticated root RCE (CVE-2026-0300)
A critical buffer overflow in the User-ID Authentication Portal service of PAN-OS allows an unauthenticated remote attacker to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls. Rated 9.3 out of 10, the flaw has reportedly been exploited since at least April 2026 by a likely state-sponsored actor, and CISA added it to its Known Exploited Vulnerabilities catalog.
How PacketViper addresses this
A static, rule-based control point becomes a single point of compromise the moment its own authentication logic breaks. PacketViper’s model does not rely on the firewall’s internal trust boundary at all — it sits inline as an agentless Layer 2 bridge and evaluates every connection attempt to a protected service, including the firewall’s own management and portal interfaces, against source reputation, geography and reconnaissance patterns. An unauthenticated exploit attempt against a portal service typically looks, from the wire, like anomalous probing before it looks like a valid session — the reconnaissance phase that Automated Moving Target Defense and Global Network Lists are built to catch before the payload is delivered.
2. Palo Alto Networks GlobalProtect — VPN authentication bypass (CVE-2026-0257)
An authentication bypass in the GlobalProtect portal and gateway let attackers skip login entirely and establish an unauthorized VPN session. Palo Alto initially rated it medium severity; within four days of public disclosure, active exploitation was confirmed and the rating was raised to critical.
How PacketViper addresses this
The four-day gap between disclosure and mass exploitation is the window PacketViper is designed to operate in without needing a CVE number at all. Because enforcement is based on live behavior rather than a signature for this specific bypass, an attacker establishing a VPN session with no prior trust relationship — from an unexpected geography, at an unusual time, with no preceding legitimate handshake — is the kind of deviation contextual filtering and trust modeling are built to flag or stop, independent of whether the gateway’s authentication logic was sound that day.
3. Fortinet FortiClient EMS — authentication bypass to full RCE (CVE-2026-35616)
An improper access control flaw in the FortiClient EMS API let attackers send crafted requests to bypass authentication and authorization entirely, achieving code execution on the underlying server with no credentials and no user interaction. Independent researchers detected active exploitation days before Fortinet’s own advisory was published — a true zero-day. CISA added it to its Known Exploited Vulnerabilities catalog within two days of disclosure.
How PacketViper addresses this
This is a management-plane API being hit directly — the kind of narrow, high-value target that passive asset discovery is meant to keep continuously mapped and watched, and that AMTD is meant to keep from being reliably found or fingerprinted in the first place. A network that does not change is a network that can be fully mapped and catalogued for later use. An EMS API sitting at a static, discoverable address is exactly the asset AMTD is designed to make unreliable to locate from outside the trust boundary.
4. Fortinet FortiCloud SSO — auth bypass on fully patched firewalls (CVE-2026-24858)
Multiple Fortinet customers reported attackers creating new local administrator accounts on FortiGate firewalls already running the latest FortiOS updates. The flaw allowed any attacker with a FortiCloud account and a registered device to bypass authentication and reach other devices tied to different customer accounts when SSO was enabled — meaning being fully patched provided no protection on its own.
How PacketViper addresses this
This is the clearest case for behavior- and trust-based enforcement over patch status alone. PacketViper models expected trust relationships between assets, and anything outside the pattern gets stopped rather than merely flagged. A brand-new local admin account appearing on a firewall, or an unfamiliar device suddenly reaching that firewall’s management plane through an SSO relationship it has never used before, is a deviation from established behavior — regardless of whether the CVE enabling it is known, patched, or even disclosed yet.
5. Check Point — VPN / Mobile Access zero-day tied to Qilin ransomware (CVE-2026-50751)
A critical authentication bypass affecting Check Point Remote Access VPN, Mobile Access and Spark Firewall products (CVSS 9.3) was found being actively exploited, with post-exploitation activity retrieving malicious payloads from attacker-controlled infrastructure and ties identified to the Qilin ransomware operation. CISA gave federal agencies a three-day window to patch.
How PacketViper addresses this
A three-day patch window is still three days of exposure across an entire fleet — which is why the moment of initial compromise matters more than the speed of the eventual patch. PacketViper’s “Hive” architecture is built around that gap: when any single unit detects malicious behavior, it blocks locally and propagates that block to every other unit across the enterprise in milliseconds, without waiting on a human to push policy. A VPN endpoint compromised at one site would not need to be independently rediscovered and blocked at every other site before containment took effect.
6. Cisco — sixth SD-WAN zero-day of 2026, plus continued ASA/FTD exploitation
Cisco patched its sixth actively-exploited SD-WAN zero-day disclosed in 2026 alone, this one tied to a sophisticated actor tracked as UAT-8616. Separately, Cisco has continued to warn of ongoing attacks against its ASA and FTD firewall lines, including a vulnerability the Interlock ransomware group exploited as a zero-day for months before disclosure. As of July 2026, 93 Cisco CVEs sit on CISA’s Known Exploited Vulnerabilities catalog.
How PacketViper addresses this
Six exploited zero-days in a single product line in a single year is a volume problem as much as a vulnerability problem — each one requires its own detection signature, its own patch cycle, and its own confirmation that no prior exploitation occurred. PacketViper does not need to know what a given exploit looks like in advance: enforcement operates on reconnaissance and behavioral deviation, which is present before almost any exploit attempt, rather than on a growing library of vulnerability-specific signatures. That does not reduce Cisco’s patch burden, but it is intended to shrink the window in which an unpatched device can be found and hit in the first place.
The common thread
Every incident above shares the same shape: a device whose entire job is to be the trust boundary had a flaw in the logic that decides who to trust, and the blast radius was the device’s full privileges — root code execution, a forged admin account, an unauthorized VPN session, a foothold for ransomware. None of these were exotic attacks. Several were found and exploited faster than the vendor could patch.
PacketViper’s positioning treats that pattern as the baseline threat model rather than the exception:
- Agentless, inline enforcement — sits in the traffic path around the firewall or VPN appliance rather than depending on that appliance’s own internal logic being sound.
- Automated Moving Target Defense (AMTD) — continuously shifts the network’s visible attack surface, so the reconnaissance that typically precedes exploitation of a management or VPN portal returns unreliable results.
- Behavioral and trust modeling — flags or blocks a new admin account, an unfamiliar device, an unexpected session, independent of whether a specific CVE is known or patched yet.
- Hive-mind propagation — a block detected at one site or unit is pushed to every other unit in the deployment in milliseconds, narrowing the window between first detection and full containment.
- Global Network Lists — automatic filtering by country, business entity and threat category before a packet is even evaluated against the protected service.
A compensating control, not a patch replacement
None of this argues against patching — it argues for not relying on patch cycles alone. Every incident above shares the same exposure window: the gap between when a flaw exists and when it is found, disclosed and fixed, a gap that AI-accelerated reconnaissance and exploitation are compressing every year. A compensating control is built to hold that window closed. Because PacketViper enforces on behavior and reconnaissance rather than a signature for a specific CVE, it does not need to know these six vulnerabilities in advance to add a layer of defense-in-depth against the pattern they represent.
Frequently asked questions
Does PacketViper replace our firewall?
No. It sits alongside the firewall, not in place of it, as an inline agentless layer in the traffic path. The point is that it does not depend on the firewall’s own authentication and management logic being sound — which is precisely what failed in all six incidents above.
How can it stop an exploit for a CVE nobody has disclosed yet?
It does not detect the exploit; it acts on what precedes and surrounds it. Enforcement operates on reconnaissance patterns, source reputation, geography and deviation from established trust relationships — signals present before almost any exploit attempt. That is a different mechanism from a signature library, and it is why a patch status of “fully current” did not protect the FortiGate customers in incident 4.
Has PacketViper been tested against these specific CVEs?
No, and this paper does not claim otherwise. It is commentary and analysis describing how the stated architecture addresses each category of exposure, not the result of independent validation against any listed CVE. The fit is worth testing directly — a proof of concept against a real environment is a standard option.
What is “Hive” propagation?
When any single PacketViper unit detects malicious behavior, it blocks locally and propagates that block to every other unit across the enterprise in milliseconds, without waiting for a human to push policy. It shortens the interval between first detection at one site and containment everywhere else.
Sources
- Hackers run code on PAN-OS firewalls as root without authentication: critical zero-day unveiled — Cybernews
- Hackers are exploiting Palo Alto GlobalProtect VPN authentication bypass (CVE-2026-0257) — Help Net Security
- Fortinet FortiClient EMS Zero-Day: CVE-2026-35616 (Active Exploitation Underway) — watchTowr
- Fortinet’s latest zero-day vulnerability carries frustrating familiarities for customers — CyberScoop
- Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751) — Rapid7
- Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026 — SecurityWeek
Test the fit against your own environment
A proof of concept runs against your real traffic — inline, agentless, no maintenance window.
Request a Proof of Concept Download the PDF ↓