logo

Patch Now: Another Palo Alto Auth Bypass Bug Under Active Exploit

ID: 55a147fa-d001-5202-b717-7ba425c3de7a

STIX ID: report--55a147fa-d001-5202-b717-7ba425c3de7a

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2026-06-01

Date Updated: 2026-06-15

Author: Elizabeth Montalbano

...
...

Attackers are actively exploiting CVE-2026-0257, an authentication-bypass flaw in Palo Alto Networks PAN-OS GlobalProtect that can allow forged authentication-override cookies to establish VPN sessions without valid credentials; Rapid7 demonstrated a PoC and observed successful exploitation across multiple customers, and CISA added the flaw to its KEV catalog — operators should apply vendor patches or disable authentication-override and use dedicated certificates immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.