Vulnerabilities
Palo Alto GlobalProtect Auth Bypass CVE-2026-0257 Is Now Under Active Exploitation
Palo Alto Networks has confirmed that attackers are actively exploiting CVE-2026-0257, an authentication-bypass flaw in PAN-OS GlobalProtect that lets them set up VPN sessions on internet-facing firewalls with no credentials. Rapid7 has observed successful intrusions.