logo

PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

ID: e86e1584-0571-5a0d-bb95-89349f2039e9

STIX ID: report--e86e1584-0571-5a0d-bb95-89349f2039e9

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-05-30

Date Updated: 2026-05-30

Author: [email protected] (The Hacker News)

...
...

Palo Alto Networks disclosed CVE-2026-0257, an authentication-bypass affecting PAN-OS GlobalProtect portals/gateways (CVSS 7.8) that can allow attackers to establish unauthorized VPN connections when authentication override cookies and a specific certificate configuration are present; Rapid7 and Palo Alto reported limited active exploitation in multiple waves and recommend urgent patching or mitigations (disable auth override or use a new certificate).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.