Back to Feed
VulnerabilitiesJun 1, 2026

Recent Palo Alto Networks Vulnerability Exploited for Weeks

CVE-2026-0257, a PAN-OS authentication bypass, was exploited within days of public disclosure.

Summary

Threat actors began exploiting CVE-2026-0257, an authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect, shortly after its public disclosure. Rapid7 observed attackers forging cookies to bypass authentication and gain VPN access to internal networks, originating from hosting providers Vultr and Dromatics Systems.

Full text

Threat actors began targeting an authentication bypass vulnerability in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS just four days after public disclosure, Rapid7 warns. Tracked as CVE-2026-0257 (CVSS score of 7.8), the high-severity security defect allows attackers to bypass restrictions and establish VPN connections to vulnerable appliances. Palo Alto Networks released fixes for the bug on May 13, noting that it affects firewalls with GlobalProtect portal or gateway enabled, under certain configurations. On Friday, the company updated its advisory to warn that threat actors are exploiting the flaw in the wild, and NIST flagged the issue as critical. “Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied,” the company says. Simultaneously, the US cybersecurity agency CISA added the CVE to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it by June 1.Advertisement. Scroll to continue reading. Palo Alto Networks and CISA did not share details on the observed exploitation, but Rapid7 revealed that threat actors started exploiting CVE-2026-0257 on May 17. “During the initial investigation, Rapid7 observed a suspicious cookie authentication to the local admin account across multiple customer environments from the same hosting provider, Vultr,” the cybersecurity firm notes. On May 21, the company says, the same threat actor launched a second wave of attacks from the hosting provider Dromatics Systems. “In this wave of exploitation, Rapid7 observed VPN IP assignment following the cookie authentication, granting them access to the internal network. At this time, Rapid7 is unable to confirm why VPN assignment occurred only for a subset of exploited customers,” the security firm says. The threat actor successfully exploited CVE-2026-0257 across multiple environments, probing the authentication bypass using forged cookies. In eight out of ten cases, the cookies were accepted without a full VPN session being established. Rapid7 has published a proof-of-concept (PoC) script to help organizations identify vulnerable Palo Alto Networks firewalls in their environments. It also released indicators of compromise (IoCs) to help defenders hunt for potential compromises. Palo Alto Networks included patches for the vulnerability in software updates for PAN-OS 12.1, 11.2, 11.1, and 10.2, and for Prisma Access 11.2.0 and 10.2.0. Organizations are advised to update to a patched iteration as soon as possible. Related: Exploit Code Published for Critical Flowise RCE Vulnerability Related: Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks Related: CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day Related:Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Chrome 148 Update Patches 151 VulnerabilitiesGeordie Raises $30 Million for AI Security and Governance PlatformCarnival Data Breach Exposed 6 Million PeopleNew BTMOB Android Malware Enables Full Device TakeoverCritical FortiClient EMS Vulnerability Exploited in Fresh AttacksGitea Vulnerability Exposed 30,000 Deployments to AttacksGoogle Unveils AI Threat Defense Platform to Fight AI-Powered CyberattacksRevEng.AI Raises $15 Million to Hunt for Flaws and Backdoors in Software Binaries Latest News As the Pentagon Pushes for Battlefield AI, Some Military Leaders Urge Caution19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root AccessRussian Spies Are Aggressively Seeking Western Technology as Sanctions Bite, Officials SayExploit Code Published for Critical Flowise RCE VulnerabilityIn Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain AttacksCharter Communications Data Breach Could Impact Nearly 5 MillionMokN Raises $15 Million for Phish-Back PlatformGogs Zero-Day Exposes Servers to Remote Code Execution Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Threat Detection and Incident Response Summit On-Demand Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization. Register Webinar: Third-Party Risk in Practice June 4, 2026 Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice. Register People on the MoveAnurag Jain has been appointed Senior Vice President of Engineering at CodeHunterCTERA has appointed Tal Sarfaty as Senior Vice President of Cybersecurity.Quantum Secure Encryption has named Michael Massing as Chief Technology Officer.More People On The MoveExpert Insights Raising the Cybersecurity Stakes: Ante up for the Agentic Era CISOs are now facing machine-speed attacks and asking, “How do I agent?” The industry must provide remediation at scale. (Nadir Izrael) Caught Off Guard: Securing AI After It Hits Production As enterprises rush AI projects into production, security teams are increasingly being forced into reactive mode. (Joshua Goldfarb) Cyber Resilience is the New Business Continuity Plan The organizations best prepared to face disruption are those that align security, continuity and risk management around what the business cannot afford to lose. (Steve Durbin) Enhancing Data Center Security Without Sacrificing Performance For AI data centers, where the stakes are the highest and performance constraints are the tightest, security and performance are no longer a zero-sum game. (Nadir Izrael) Is the SOC Obsolete, and We Just Haven’t Admitted It Yet? Many AI-first enterprises have already embraced sovereign architectures for general AI initiatives; cybersecurity—and the SOC—should be next. (Danelle Au) Flipboard Reddit Whatsapp Whatsapp Email

Entities

PAN-OS (product)Palo Alto Networks (vendor)Rapid7 (vendor)GlobalProtect (product)VPN (technology)