logo

Palo Alto PAN-OS Authentication Bypass Vulnerability Actively Exploited in the Wild

ID: 0c2abe7c-5db6-5834-93c0-9c873a08676f

STIX ID: report--0c2abe7c-5db6-5834-93c0-9c873a08676f

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-05-30

Date Updated: 2026-05-30

Author: Eswar

...
...

A vulnerability (CVE-2026-0257) in Palo Alto Networks PAN-OS and Prisma Access enabling forged GlobalProtect authentication-override cookies is being actively exploited in the wild; Rapid7 observed two attack waves that probed and in some cases established full VPN sessions, CISA added the CVE to its KEV catalog, and the report provides IOCs (source IPs, machine names, spoofed MAC) plus specific PAN-OS/Prisma Access updates and mitigations to apply immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.