Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
palo-alto-cve-2026-0265-checker — Python script to sweep a fleet of Palo Alto firewalls and Panoramas via SSH, check PAN-OS version against CVE-2026-0265 (Authentication Bypass via Cloud Authentication Service), detect whether CAS is actually configured, and report exploitability in a color-coded summary table. | Kitploit
Tools/GitHubGitHub/tstephens1080/palo-alto-cve-2026-0265-checker
Vulnerability ScannersVulnerability AnalysisConfiguration AuditingNetwork SecurityCloud SecurityAuthentication
GitHubtstephens1080/palo-alto-cve-2026-0265-checker

palo-alto-cve-2026-0265-checker

Python script to sweep a fleet of Palo Alto firewalls and Panoramas via SSH, check PAN-OS version against CVE-2026-0265 (Authentication Bypass via Cloud Authentication Service), detect whether CAS is actually configured, and report exploitability in a color-coded summary table.

View Repository
124 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-0265 Risk Checker for Palo Alto PAN-OS A Python script that connects to a list of Palo Alto Networks firewalls and Panorama appliances over SSH and reports each device's exposure to CVE-2026-0265 — an authentication bypass vulnerability in PAN-OS affecting devices with the Cloud Authentication Service (CAS) enabled. Rather than relying solely on a version match (which over-reports), the script also checks whether CAS is actually configured on each device and distinguishes between vulnerable, affected-but-not-exploitable, and safe.

Why this script exists The official advisory lists every PAN-OS version below a fixed hotfix as "affected." In practice, the bug only matters if you've configured a CAS-based authentication profile. A naïve version scan flags every device on an older hotfix as vulnerable, leaving you no way to prioritize patching across a large fleet. This script gives you the full picture in one pass: AFFECTED BY CVE — purely a version-range check against the advisory. CAS — does the device actually have a CAS authentication profile defined? STATUS — combined verdict: VULNERABLE — affected version and CAS configured (true exposure) NOT_EXPLOITABLE — affected version, but no CAS profile is defined; the vulnerable code path is not reachable SAFE — running a fixed or unaffected version

Features Connects to every device in parallel (configurable worker count; default 8). Single SSH session per device, runs only two read-only show commands — no configuration changes. Handles HA-state prompts (e.g. user@host(active)>) and disables the PAN-OS pager so output isn't truncated. Color-coded summary table (red / yellow / green) with separate AFFECTED BY CVE, CAS, and STATUS columns. Works against both firewalls and Panorama (same CLI on both). Cross-platform: Windows / macOS / Linux. ANSI colors auto-enabled on Windows 10+. Graceful SSH exit — sends exit before closing so PAN-OS audit logs see a clean logout rather than a transport drop.

Requirements Python 3.8 or newer paramiko (pip install paramiko) A read-only admin account that exists on every device in your list (TACACS+, RADIUS, SAML, or local — anything works as long as the same credentials authenticate everywhere). SSH (TCP/22) reachability from wherever you run the script to each device's management interface.

Installation

git clone https://github.com/YOUR_USERNAME/palo-alto-cve-2026-0265-checker.git
cd palo-alto-cve-2026-0265-checker
pip install paramiko

Usage Open check_cve_2026_0265.py and edit the DEVICES list near the top with your own hostnames and management IPs: python DEVICES = [ ("fw1-prod-region1", "192.0.2.10"), ("fw2-prod-region1", "192.0.2.11"), ("panorama1", "198.51.100.10"), # ... ] Optionally change DEFAULT_USER to your standard read-only admin account name. Run the script: bash python check_cve_2026_0265.py Enter your SSH username and password when prompted. The same credentials are reused for every device.

Sample output

================================================================================
 CVE-2026-0265 Risk Checker  -  Multi-device PAN-OS sweep
================================================================================
 Devices in list: 6
 Parallel workers: 8

SSH username for all devices [admin]:
Password for admin:

 Checking devices (results appear as each finishes) ...
 ------------------------------------------------------------------------------
 [ 1/ 6] fw1-prod-region1                 192.0.2.10       NOT_EXPLOITABLE  11.1.4-h7    CAS:no
 [ 2/ 6] fw2-prod-region1                 192.0.2.11       NOT_EXPLOITABLE  11.1.4-h7    CAS:no
 [ 3/ 6] fw1-prod-region2                 192.0.2.20       SAFE             11.0.3-h10   CAS:no
 [ 4/ 6] fw2-prod-region2                 192.0.2.21       SAFE             11.0.3-h10   CAS:no
 [ 5/ 6] panorama1-region1                198.51.100.10    NOT_EXPLOITABLE  11.2.7-h4    CAS:no
 [ 6/ 6] panorama2-region2                198.51.100.20    NOT_EXPLOITABLE  11.2.7-h4    CAS:no
 ------------------------------------------------------------------------------
 Completed in 18.4 seconds
Download Tool