Palo Alto Networks has confirmed active exploitation of a medium-severity authentication bypass vulnerability, tracked as CVE-2026-0257, affecting GlobalProtect portals and gateways within its PAN-OS and Prisma Access software.
Key Points
- The vulnerability, assigned a CVSS score of 7.8, allows unauthorized actors to establish VPN connections by bypassing security restrictions.
- Exploitation attempts were first identified by Rapid7 on May 17, 2026, with a second wave of activity occurring on May 21.
- Affected systems include firewalls where authentication override cookies are enabled alongside specific certificate configurations.
- Palo Alto Networks released an official advisory on May 13, 2026, urging administrators to apply available patches immediately.
- Temporary mitigations include disabling the authentication override feature or generating a new, dedicated certificate for authentication processes.