Skip to content
The Nexus
DossierENTITY

CVE-2026-0257

Coverage of CVE-2026-0257 in the Nexus archive.

Earliest in view: May 30 · 06:41 UTCMost recent: Jun 15 · 06:17 UTC
Co-mentioned in this coverage
Recent coverage
  • SECURITYJun 15 · 06:17 UTCTHE HACKER NEWS
    Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw

    Palo Alto Networks has observed active exploitation of a PAN-OS vulnerability (CVE-2026-0257) in GlobalProtect portals, allowing unauthorized access via an authentication bypass flaw. The vulnerability affects portal and gateway components of PAN-OS software with a CVSS score of 7.8.

  • SECURITYJun 1 · 22:29 UTCCYBERSCOOP
    Attackers are exploiting Palo Alto Networks defect that initially flew under the radar

    Palo Alto Networks' CVE-2026-0257 vulnerability, initially rated medium severity, was escalated to critical after active exploitation was confirmed. Attackers exploit the flaw to bypass authentication and establish unauthorized VPN connections, leveraging a publicly available TLS certificate to forge valid authentication cookies.

  • SECURITYJun 1 · 12:15 UTCTHE REGISTER
    Palo Alto VPN bug graduates from advisory to active exploitation

    Palo Alto Networks disclosed a critical security flaw, CVE-2026-0257, in PAN-OS GlobalProtect that allows attackers to bypass authentication and gain unauthorized VPN access. Researchers at Rapid7 confirmed active exploitation since May 17, prompting Palo Alto to elevate the severity rating and CISA to add it to its exploited vulnerabilities catalog with a June 1 patch deadline.

  • SECURITYMay 30 · 18:02 UTCBLEEPING COMPUTER
    Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks

    Palo Alto Networks warns that hackers are exploiting a PAN-OS GlobalProtect authentication bypass flaw (CVE-2026-0257) in attacks targeting corporate networks. The vulnerability allows unauthorized access to systems using the GlobalProtect VPN solution.

  • SECURITYMay 30 · 06:41 UTCTHE HACKER NEWS
    PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

    Palo Alto Networks has warned that a medium-severity authentication bypass vulnerability (CVE-2026-0257) in PAN-OS and Prisma Access is being actively exploited. The flaw allows attackers to establish unauthorized VPN connections.

CVE-2026-0257 · Dossier · The Nexus