SECURITYTHE REGISTER
Palo Alto VPN bug graduates from advisory to active exploitation
Palo Alto Networks disclosed a critical security flaw, CVE-2026-0257, in PAN-OS GlobalProtect that allows attackers to bypass authentication and gain unauthorized VPN access. Researchers at Rapid7 confirmed active exploitation since May 17, prompting Palo Alto to elevate the severity rating and CISA to add it to its exploited vulnerabilities catalog with a June 1 patch deadline.
Mentioned
Related Signal
Adjacent reporting
- cPanel’s authentication bypass bug is being exploited in the wild, CISA warns
- PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation
- Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks
- Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV
- Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202
- Fortinet Issues Emergency Patch for FortiClient Zero-Day