{"id":15275,"date":"2026-05-31T04:02:55","date_gmt":"2026-05-31T04:02:55","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=15275"},"modified":"2026-05-31T04:02:55","modified_gmt":"2026-05-31T04:02:55","slug":"pan-os-globalprotect-authentication-bypass-cve-2026-0257-below-lively-exploitation","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=15275","title":{"rendered":"PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Below Lively Exploitation"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Could 30, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Community Safety<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgkaW0i4ALAlpWQ_cOjfhoqUlNgMlZysJA6ay0qPViGI_KxEEG-Hh0KdtWLqBXDH42ZBGSONs0ZJuzOqdRF7vbx6Xa9J8HlP60lY45JHy0ivdRQs0exe4wZT2lI3TW4oDO-XXPVz2pek2M3izLqT3ONwq2iuHPN31ZZvK3jl0zIDq_h5XF1CTRk7fUPzjEQ\/s1600\/panos.jpg\" style=\"display: block; padding: 1em 0; text-align: center; clear: left; float: left;\"><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"470\" data-original-width=\"900\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgkaW0i4ALAlpWQ_cOjfhoqUlNgMlZysJA6ay0qPViGI_KxEEG-Hh0KdtWLqBXDH42ZBGSONs0ZJuzOqdRF7vbx6Xa9J8HlP60lY45JHy0ivdRQs0exe4wZT2lI3TW4oDO-XXPVz2pek2M3izLqT3ONwq2iuHPN31ZZvK3jl0zIDq_h5XF1CTRk7fUPzjEQ\/s1600\/panos.jpg\"\/><\/a><\/div>\n<p>Palo Alto Networks has warned {that a} just lately disclosed medium-severity safety flaw impacting PAN-OS and Prisma Entry has come below lively exploitation within the wild.<\/p>\n<p>The vulnerability, tracked as <b><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/security.paloaltonetworks.com\/CVE-2026-0257\">CVE-2026-0257<\/a><\/b> (CVSS rating: 7.8), refers to a case of authentication bypass that may very well be exploited by dangerous actors to arrange VPN connections.<\/p>\n<p>&#8220;Authentication bypass vulnerabilities within the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS\u00ae software program permit the attacker to bypass safety restrictions and set up an unauthorized VPN connection,&#8221; Palo Alto Networks stated in an advisory launched on Could 13, 2026.<\/p>\n<p>The problem particularly impacts firewalls with GlobalProtect portal or gateway configured when authentication override cookies are enabled and a particular certificates configuration exists, the community safety firm stated.<\/p>\n<p>In an replace to its advisory on Could 29, 2026, Palo Alto Networks stated it has &#8220;turn into conscious of restricted exploit makes an attempt on unpatched PAN-OS units with out mitigations utilized.<\/p>\n<p><\/p>\n<p>The event comes after Rapid7 <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.rapid7.com\/blog\/post\/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257\/\">revealed<\/a> it recognized profitable exploitation throughout quite a few prospects, with the earliest efforts courting again to Could 17, 2026, adopted by a second wave on Could 21. Each the exploitation units are assessed to be the work of the identical risk actor.<\/p>\n<p>The exercise noticed within the second wave concerned VPN IP project following the cookie authentication in two circumstances, granting the attacker entry to the inner community. No follow-on exercise within the buyer environments the place a VPN session was established, the cybersecurity vendor added.<\/p>\n<p>&#8220;An authentication bypass in an edge dealing with enterprise VPN equipment can have vital impression to affected organizations,&#8221; Rapid7 stated. &#8220;As such, organizations operating affected home equipment are urged to improve to a vendor equipped patch on an pressing foundation.&#8221;<\/p>\n<p>As momentary mitigations, it is advisable to both disable the authentication override characteristic or generate a brand new certificates to make use of completely for the authentication override characteristic.<\/p>\n<p>The exploitation of CVE-2026-0257 follows a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2026\/05\/threat-actors-exploit-critical.html\">report<\/a> from Arctic Wolf in regards to the continued weaponization of a important, now-patched safety flaw impacting FortiClient Endpoint Administration Server (EMS) deployments (CVE-2026-35616, CVSS rating: 9.1) to ship credential-stealing malware referred to as EKZ Infostealer.<\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Could 30, 2026Vulnerability \/ Community Safety Palo Alto Networks has warned {that a} just lately disclosed medium-severity safety flaw impacting PAN-OS and Prisma Entry has come below lively exploitation within the wild. The vulnerability, tracked as CVE-2026-0257 (CVSS rating: 7.8), refers to a case of authentication bypass that may very well be exploited by [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":15277,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[768,3369,210,9261,2036,9260,9259],"class_list":["post-15275","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-active","tag-authentication","tag-bypass","tag-cve20260257","tag-exploitation","tag-globalprotect","tag-panos"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/15275","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=15275"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/15275\/revisions"}],"predecessor-version":[{"id":15276,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/15275\/revisions\/15276"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/15277"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=15275"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=15275"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=15275"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-05-31 17:24:12 UTC -->