Rapid7 observes new Palo Alto VPN flaw exploited in the wild to bypass GlobalProtect authentication
- Critical PAN‑OS flaw exploited in the wild
- Authentication bypass enables unauthorized VPN access
- CISA added CVE‑2026‑0257 to KEV catalog
A recently discovered vulnerability in PAN-OS, the operating system powering Palo Alto’s firewalls, is being actively exploited in the wild, researchers are saying, urging customers to apply the provided patch as soon as possible.
In mid-May this year, Palo Alto disclosed an authentication bypass flaw in the Global Protect portal and gateway that allows threat actors to work around security restrictions and establish an unauthorized VPN connection. The bug is now tracked as CVE-2026-0257, and assigned a severity score of 9.1/10 (critical).
Earlier this week, security researchers Rapid7 said they saw threat actors successfully leveraging this bug in attacks: “Rapid7 MDR identified successful exploitation across numerous customers, however we did not observe any indication of successful lateral movement from the devices,” Rapid7 said in its report. “The earliest date for...
Copyright of this story solely belongs to techradar.com. To see the full text click HERE