GlobalProtect
Coverage of GlobalProtect in the Nexus archive.
- Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw
Palo Alto Networks has observed active exploitation of a PAN-OS vulnerability (CVE-2026-0257) in GlobalProtect portals, allowing unauthorized access via an authentication bypass flaw. The vulnerability affects portal and gateway components of PAN-OS software with a CVSS score of 7.8.
- Palo Alto VPN bug graduates from advisory to active exploitation
Palo Alto Networks disclosed a critical security flaw, CVE-2026-0257, in PAN-OS GlobalProtect that allows attackers to bypass authentication and gain unauthorized VPN access. Researchers at Rapid7 confirmed active exploitation since May 17, prompting Palo Alto to elevate the severity rating and CISA to add it to its exploited vulnerabilities catalog with a June 1 patch deadline.
- Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks
Palo Alto Networks warns that hackers are exploiting a PAN-OS GlobalProtect authentication bypass flaw (CVE-2026-0257) in attacks targeting corporate networks. The vulnerability allows unauthorized access to systems using the GlobalProtect VPN solution.