logo

CVE-2026-0257

ID: e1748842-28cf-52ee-8283-a3c91057b969

STIX ID: report--e1748842-28cf-52ee-8283-a3c91057b969

Feed Name: Arctic Wolf Blog

Threat Score
80/100

Date Published: 2026-06-04

Date Updated: 2026-06-17

...
...

Arctic Wolf observed active exploitation of CVE-2026-0257, a high-severity (CVSS 7.8) authentication bypass in Palo Alto Networks GlobalProtect that allows attackers to forge authentication-override cookies and gain unauthorized VPN sessions (including administrative access); exploitation since mid-May 2026 has led to configuration disclosure, IPsec tunnel setup, and lateral movement, and the report provides IoCs, affected versions, and remediation and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.