Attackers are exploiting a security vulnerability in Palo Alto Networks' PAN-OS GlobalProtect VPN technology that allows them to bypass authentication and gain VPN access without valid credentials. In May, Palo Alto Networks (PAN) disclosed and fixed the flaw, tracked as CVE-2026-0257, but it updated the advisory last week to note that there have been "limited exploit attempts on unpatched PAN-OS devices without mitigations applied." That update came on the heels of research from Rapid7 that identified successful exploitation "across numerous customers" as early as May 17, according to a report, also published last week. And on May 29, the Cybersecurity and Infrastructure Security Agency (CISA) also added the flaw to its Known Exploited Vulnerabilities (KEV) catalog. The bug affects the GlobalProtect portal and gateway for the PAN-OS software across various versions, which are listed in the advisory. An internal researcher at the company discovered the flaw, which received an initial CVSS score of 7.8 that rated it of "medium" severity, since it requires firewalls with the GlobalProtect portal or gateway configured to have both authentication override cookies enabled and a specific certificate configuration. But that hasn't stopped cyberattackers. Denis Calderon, Suzu Labs CTO and principal, tells Dark Reading that the CVSSv4 score of 7.8 set the wrong tone from the start, though he doesn't disagree with the rating on principle. "The rating itself is basically correct based o...
Patch Now: Another Palo Alto Auth Bypass Bug Under Active Exploit
Dark Reading
·Elizabeth Montalbano
·Published Jun 1, 2026
·Updated
Affected Software
2 affected components
Palo Alto Networks PAN-OS GlobalProtect portal
Palo Alto Networks PAN-OS GlobalProtect gateway
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a vulnerability in Palo Alto Networks' GlobalProtect VPN technology that is being actively exploited.
2
What security implications are discussed?
The bug allows attackers to bypass authentication, gaining unauthorized VPN access without valid credentials.
3
What products or software are affected?
The vulnerability affects Palo Alto Networks' PAN-OS GlobalProtect portal and PAN-OS GlobalProtect gateway.
4
When was the vulnerability disclosed and fixed?
Palo Alto Networks disclosed and fixed the vulnerability in May 2026.
5
What is the CVE identifier for this vulnerability?
The vulnerability is tracked as CVE-2026-0257.