Rapid7 observes new Palo Alto VPN flaw exploited in the wild to bypass GlobalProtect authentication



  • Critical PAN‑OS flaw exploited in the wild
  • Authentication bypass enables unauthorized VPN access
  • CISA added CVE‑2026‑0257 to KEV catalog

A recently discovered vulnerability in PAN-OS, the operating system powering Palo Alto’s firewalls, is being actively exploited in the wild, researchers are saying, urging customers to apply the provided patch as soon as possible.

In mid-May this year, Palo Alto disclosed an authentication bypass flaw in the Global Protect portal and gateway that allows threat actors to work around security restrictions and establish an unauthorized VPN connection. The bug is now tracked as CVE-2026-0257, and assigned a severity score of 9.1/10 (critical).

https://cdn.mos.cms.futurecdn.net/jNA4KFmhg8oX9bYUYaaySG-1920-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img