logo

Palo Alto Networks GlobalProtect Authentication Bypass: What Security Teams Should Know About CVE-2026-0257 

ID: 2e3253ce-7ec7-5985-9890-0c5c34cd99ea

STIX ID: report--2e3253ce-7ec7-5985-9890-0c5c34cd99ea

Feed Name: Security Boulevard

Threat Score
85/100

Date Published: 2026-06-09

Date Updated: 2026-06-10

Author: Dr. Yunfei Ge

...
...

The report details CVE-2026-0257, an authentication-bypass vulnerability in Palo Alto Networks GlobalProtect portals and gateways that can accept forged authentication override cookies under specific certificate configurations, allowing unauthorized VPN access and potential internal network compromise; exploitation was observed in the wild and CISA listed the CVE in its Known Exploited Vulnerabilities catalog, prompting urgent upgrade and monitoring guidance for affected PAN-OS and Prisma Access deployments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.