Description
This module checks a PAN-OS GlobalProtect portal for CVE-2026-0265 using the Bishop Fox scanner decision flow. It performs anonymous GET requests to the GlobalProtect prelogin endpoint, retrying transient failures and HTTP 503 responses, then checks whether CAS authentication is enabled, decodes the embedded SAML/JWT token when present, extracts PanOSversion, and compares it against the advisory version matrix.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use auxiliary/scanner/http/panos/cve_2026_0265msf undefined(cve_2026_0265) > show actions ...actions...msf undefined(cve_2026_0265) > set ACTION < action-name >msf undefined(cve_2026_0265) > show options ...show and set options...msf undefined(cve_2026_0265) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub