Active Exploitation of PAN OS Flaw
Palo Alto Networks firewalls are under active attack through a PAN OS vulnerability.
CVE-2026-0257 is an authentication bypass in the GlobalProtect portal and gateway that lets unauthenticated attackers forge session cookies and establish unauthorized VPN connections. CVSS 7.8, actively exploited in the wild.
Affects PAN OS versions before 11.1.5 h1, 11.2.4 h4, and 12.1.2 h4 on firewalls and Panorama appliances.
Palo Alto confirmed limited exploitation; Rapid7 observed two attack waves starting May 18 and May 21 across multiple customer environments.
