Active Exploitation of PAN-OS Vulnerability CVE-2026-0257 (infosecurity-magazine.com)
- CVE-2026-0257: authentication bypass in PAN-OS GlobalProtect
- CVSS 7.8, actively exploited since May 18, 2026
- Patch released May 13, 2026; CISA mandate to patch by June 1, 2026
"Palo Alto Networks has warned that a high-severity authentication bypass vulnerability in PAN-OS, CVE-2026-0257, is being actively exploited. The flaw affects GlobalProtect portal and gateway when authentication override cookies are enabled. Patched on May 13, 2026, exploitation attempts began May 18 and May 21. Rapid7 observed two waves, likely from the same actor, granting unauthorized VPN access via forged cookies. Organizations are urged to patch immediately or apply mitigations: disable authentication override or generate a dedicated certificate. CISA added the bug to its Known Exploited Vulnerabilities catalog, mandating patching by June 1, 2026."
no comments yet.