CVE Tools

Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257

Palo Alto Unit 42By Andy Piazza, Unit 423 min read

Reported exploitedPAN-OSGlobalProtect (portal and gateway)
Read at Palo Alto Unit 42

Below is the opening; the full story is at Palo Alto Unit 42.

From Palo Alto Unit 42

Palo Alto Networks Unit 42 has observed active exploitation of PAN-OS vulnerability CVE-2026-0257">CVE-2026-0257 by an unidentified threat actor attempting to access GlobalProtect. This security flaw involves an authentication bypass in the portal and gateway components of vulnerable versions of PAN-OS® software, which could allow unauthorized attackers to circumvent security controls and initiate VPN connections. This CVE was added to the Known Exploited Vulnerability (KEV) catalog on May 29.…

Continue at Palo Alto Unit 42

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store