CVE-2026-0257 is a high-severity authentication bypass vulnerability affecting the GlobalProtect portal and gateway components of Palo Alto Networks PAN-OS and certain Prisma Access deployments. Successful exploitation allows an unauthenticated remote attacker to bypass security controls and establish unauthorized VPN connections without valid credentials. Palo Alto Networks, Unit 42, Rapid7, and other security researchers have confirmed active exploitation in the wild, prompting inclusion in CISA's Known Exploited Vulnerabilities (KEV) catalog. The vulnerability impacts deployments that use GlobalProtect authentication override cookies in combination with specific certificate configurations. Threat actors can forge or manipulate authentication cookies to circumvent normal authentication requirements and gain network access.
Recent news and incidents related to cybersecurity threats encompassing various events such as data breaches, cyber-attacks, security incidents, and vulnerabilities discovered.
July 21, 2026: Arctic Wolf investigated multiple distinct intrusions during June 2026 that resulted in Qilin ransomware deployment, all originating from exploitation of CVE-2026-0257 against Palo Alto Networks firewall appliances.
June 09, 2026: Ongoing exploitation activity continues targeting exposed GlobalProtect services.
May 29, 2026: Added to CISA Known Exploited Vulnerabilities (KEV) catalog.
May 17, 2026: Earliest exploitation activity observed by Rapid7 MDR.
May 13, 2026: Palo Alto Networks publishes advisory and CVE-2026-0257 is disclosed.
Mitigate security threats and vulnerabilities by leveraging the range of FortiGuard Services.
Assisted Response Services
Attack Surface Hardening
Information gathered from analyzing ongoing cybersecurity events including threat actors, their tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), malware and related vulnerabilities.
Sources of information in support and relation to this Outbreak and vendor.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
