logo

U.S. CISA adds Palo Alto Networks PAN-OS flaw to its Known Exploited Vulnerabilities catalog

ID: f216e1dd-22a1-5ab5-9dbf-db51a40e65af

STIX ID: report--f216e1dd-22a1-5ab5-9dbf-db51a40e65af

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-06-01

Date Updated: 2026-06-01

Author: Pierluigi Paganini

...
...

CISA added PAN-OS CVE-2026-0257 to its Known Exploited Vulnerabilities catalog after Rapid7 observed active exploitation of an authentication-bypass flaw in GlobalProtect portal/gateway. The vulnerability—exploitable when the same certificate is used for HTTPS and cookie encryption—allows attackers to forge cookies and obtain VPN access; Rapid7 observed multiple waves of exploitation, published a PoC and IOCs, and recommends patching or mitigations immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.