logo

PAN-OS Authentication Bypass Flaw Exploited in the Wild

ID: 8ef3cde0-fcd8-5fad-a158-e3a7a35cc951

STIX ID: report--8ef3cde0-fcd8-5fad-a158-e3a7a35cc951

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-05-30

Date Updated: 2026-05-30

Author: Ddos

...
...

**Critical PAN-OS authentication bypass (CVE-2026-0257) is being actively exploited against GlobalProtect VPN gateways worldwide, allowing unauthenticated attackers to forge cookies and gain VPN access when devices reuse portal certificates and omit signature verification; investigators observed multiple exploitation waves (May 17 and May 21) tied to the same actor and recommend immediate patching or temporary configuration changes (disable authentication override or use a dedicated cookie certificate).**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.