CRITICAL ⚡ MUST-KNOW
PAN-OS GlobalProtect CVE-2026-0257 Authentication Bypass Under Active Exploitation
Palo Alto Networks has confirmed that CVE-2026-0257, an authentication bypass in PAN-OS and Prisma Access GlobalProtect, is under active exploitation in the wild. The flaw carries a CVSS score of 7.8 and allows unauthenticated attackers to establish unauthorized VPN connections by bypassing the GlobalProtect authentication layer.
Organizations running PAN-OS with GlobalProtect enabled should treat this as an emergency patch. Until patched, consider restricting GlobalProtect portal/gateway exposure or enabling Threat Prevention signatures if available. Active exploitation means opportunistic attackers are already probing internet-facing instances — prioritize remediation over the next 24–48 hours.