Vulnerabilities Recent Palo Alto Networks Vulnerability Exploited for Weeks Hackers began exploiting CVE-2026-0257, an authentication bypass in Palo Alto Networks PAN-OS, four days after public disclosure. By Ionut Arghire | June 1, 2026 (6:00 AM ET) Flipboard Reddit Whatsapp Whatsapp Email Threat actors began targeting an authentication bypass vulnerability in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS just four days after public disclosure, Rapid7 warns. Tracked as CVE-2026-0257 (CVSS score of 7.8), the high-severity security defect allows attackers to bypass restrictions and establish VPN connections to vulnerable appliances. Palo Alto Networks released fixes for the bug on May 13, noting that it affects firewalls with GlobalProtect portal or gateway enabled, under certain configurations. On Friday, the company updated its advisory to warn that threat actors are exploiting the flaw in the wild, and NIST flagged the issue as critical. “Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied,” the company says. Simultaneously, the US cybersecurity agency CISA added the CVE to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it by June 1. Advertisement. Scroll to continue reading. Palo Alto Networks and CISA did not share details on the observed exploitation, but Rapid7 revealed that threat actors started exploiting CVE-2026-0257 on May 17. “During the initial investigation, Rapid7 observed a suspicious cookie authentication to the local admin account across multiple customer environments from the same hosting provider, Vultr,” the cybersecurity firm notes. On May 21, the company says, the same threat actor launched a second wave of attacks from the hosting provider Dromatics Systems. “In this wave of exploitation, Rapid7 observed VPN IP assignment following the cookie authentication, granting them access to the internal network. At this time, Rapid7 is unable to confirm why VPN assignment occurred only for a subset of exploited customers,” the security firm says. The threat actor successfully exploited CVE-2026-0257 across multiple environments, probing the authentication bypass using forged cookies. In eight out of ten cases, the cookies were accepted without a full VPN session being established. Rapid7 has published a proof-of-concept (PoC) script to help organizations identify vulnerable Palo Alto Networks firewalls in their environments. It also released indicators of compromise (IoCs) to help defenders hunt for potential compromises. Palo Alto Networks included patches for the vulnerability in software updates for PAN-OS 12.1, 11.2, 11.1, and 10.2, and for Prisma Access 11.2.0 and 10.2.0. Organizations are advised to update to a patched iteration as soon as possible. Related: Exploit Code Published for Critical Flowise RCE Vulnerability Related: Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks Related: CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day Related: Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Geordie Raises $30 Million for AI Security and Governance Platform Carnival Data Breach Exposed 6 Million People New BTMOB Android Malware Enables Full Device Takeover Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks Gitea Vulnerability Exposed 30,000 Deployments to Attacks Google Unveils AI Threat Defense Platform to Fight AI-Powered Cyberattacks RevEng.AI Raises $15 Million to Hunt for Flaws and Backdoors in Software Binaries GlassWorm Botnet Disrupted Latest News Russian Spies Are Aggressively Seeking Western Technology as Sanctions Bite, Officials Say Exploit Code Published for Critical Flowise RCE Vulnerability In Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain Attacks Charter Communications Data Breach Could Impact Nearly 5 Million MokN Raises $15 Million for Phish-Back Platform Gogs Zero-Day Exposes Servers to Remote Code Execution California Sues 23andMe, Alleging It Failed to Protect User Data in 2023 Breach Chrome 148 Update Patches 151 Vulnerabilities Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Threat Detection and Incident Response Summit On-Demand Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization. Register Webinar: Third-Party Risk in Practice June 4, 2026 Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice. Register People on the Move Anurag Jain has been appointed Senior Vice President of Engineering at CodeHunter CTERA has appointed Tal Sarfaty as Senior Vice President of Cybersecurity. Quantum Secure Encryption has named Michael Massing as Chief Technology Officer. More People On The Move Expert Insights Raising the Cybersecurity Stakes: Ante up for the Agentic Era CISOs are now facing machine-speed attacks and asking, “How do I agent?” The industry must provide remediation at scale. (Nadir Izrael) Caught Off Guard: Securing AI After It Hits Production As enterprises rush AI projects into production, security teams are increasingly being forced into reactive mode. (Joshua Goldfarb) Cyber Resilience is the New Business Continuity Plan The organizations best prepared to face disruption are those that align security, continuity and risk management around what the business cannot afford to lose. (Steve Durbin) Enhancing Data Center Security Without Sacrificing Performance For AI data centers, where the stakes are the highest and performance constraints are the tightest, security and performance are no longer a zero-sum game. (Nadir Izrael) Is the SOC Obsolete, and We Just Haven’t Admitted It Yet? Many AI-first enterprises have already embraced sovereign architectures for general AI initiatives; cybersecurity—and the SOC—should be next. (Danelle Au) Flipboard Reddit Whatsapp Whatsapp Email
The vulnerability CVE-2026-0257 (CVSS 9.1 CRITICAL) is an authentication bypass in Palo Alto Networks PAN-OS GlobalProtect portal and gateway, exploited via forged cookies to establish unauthorized VPN connections. Affected versions are PAN-OS prior to 10.2.7. The fixed version is PAN-OS 10.2.7, and immediate patching is required as active exploitation is occurring.