Rapid7 Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257)
Reported exploitedPAN-OSPrisma Access Read at Rapid7 Blog
Below is the opening; the full story is at Rapid7 Blog.
From Rapid7 Blog
Overview
On May 13, 2026, Palo Alto Networks published a security CVE-2026-0257">advisory for CVE-2026-0257, a medium severity authentication bypass affecting PAN-OS and Prisma Access when a specific configuration is present. Successful exploitation of this vulnerability allows a remote unauthenticated attacker to successfully establish a VPN connection through the GlobalProtect gateway of an affected appliance.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.