
Pythonスクリプトで、SSH経由でPalo AltoファイアウォールとPanoramaのフリートをスイープし、PAN-OSバージョンをCVE-2026-0265(クラウド認証サービスを介した認証バイパス)と照合して確認し、CASが実際に設定されているかを検出し、色分けされた要約テーブルで悪用可能性を報告します。
VULNERABLE — affected version and CAS configured (true exposure)
NOT_EXPLOITABLE — affected version, but no CAS profile is defined; the vulnerable code path is not reachable
SAFE — running a fixed or unaffected versionshow commands — no configuration changes.
Handles HA-state prompts (e.g. user@host(active)>) and disables the PAN-OS pager so output isn't truncated.
Color-coded summary table (red / yellow / green) with separate AFFECTED BY CVE, CAS, and STATUS columns.
Works against both firewalls and Panorama (same CLI on both).
Cross-platform: Windows / macOS / Linux. ANSI colors auto-enabled on Windows 10+.
Graceful SSH exit — sends exit before closing so PAN-OS audit logs see a clean logout rather than a transport drop.paramiko (pip install paramiko)
A read-only admin account that exists on every device in your list (TACACS+, RADIUS, SAML, or local — anything works as long as the same credentials authenticate everywhere).
SSH (TCP/22) reachability from wherever you run the script to each device's management interface.Installation
git clone https://github.com/YOUR_USERNAME/palo-alto-cve-2026-0265-checker.git
cd palo-alto-cve-2026-0265-checker
pip install paramiko
check_cve_2026_0265.py and edit the DEVICES list near the top with your own hostnames and management IPs:
python DEVICES = [ ("fw1-prod-region1", "192.0.2.10"), ("fw2-prod-region1", "192.0.2.11"), ("panorama1", "198.51.100.10"), # ... ]
Optionally change DEFAULT_USER to your standard read-only admin account name.
Run the script:
bash python check_cve_2026_0265.py
Enter your SSH username and password when prompted. The same credentials are reused for every device.Sample output
================================================================================
CVE-2026-0265 Risk Checker - Multi-device PAN-OS sweep
================================================================================
Devices in list: 6
Parallel workers: 8
SSH username for all devices [admin]:
Password for admin:
Checking devices (results appear as each finishes) ...
------------------------------------------------------------------------------
[ 1/ 6] fw1-prod-region1 192.0.2.10 NOT_EXPLOITABLE 11.1.4-h7 CAS:no
[ 2/ 6] fw2-prod-region1 192.0.2.11 NOT_EXPLOITABLE 11.1.4-h7 CAS:no
[ 3/ 6] fw1-prod-region2 192.0.2.20 SAFE 11.0.3-h10 CAS:no
[ 4/ 6] fw2-prod-region2 192.0.2.21 SAFE 11.0.3-h10 CAS:no
[ 5/ 6] panorama1-region1 198.51.100.10 NOT_EXPLOITABLE 11.2.7-h4 CAS:no
[ 6/ 6] panorama2-region2 198.51.100.20 NOT_EXPLOITABLE 11.2.7-h4 CAS:no
------------------------------------------------------------------------------
Completed in 18.4 seconds