Palo Alto PAN-OS Authentication Bypass Vulnerability Actively Exploited in the Wild
ID: 0c2abe7c-5db6-5834-93c0-9c873a08676f
STIX ID: report--0c2abe7c-5db6-5834-93c0-9c873a08676f
Feed Name: GBHackers
Threat Score
A vulnerability (CVE-2026-0257) in Palo Alto Networks PAN-OS and Prisma Access enabling forged GlobalProtect authentication-override cookies is being actively exploited in the wild; Rapid7 observed two attack waves that probed and in some cases established full VPN sessions, CISA added the CVE to its KEV catalog, and the report provides IOCs (source IPs, machine names, spoofed MAC) plus specific PAN-OS/Prisma Access updates and mitigations to apply immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
