discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

Palo Alto Networks says CVE-2026-0257 is being actively exploited against PAN-OS and Prisma Access, putting VPN access and internal networks at risk.

By Ravie Lakshmanan·May 30·thehackernews.com·2 min read

Intelligence analysis by GPT-5.4 Mini

PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation
Image: thehackernews.com

Palo Alto Networks warned that CVE-2026-0257, an authentication bypass in GlobalProtect, is being exploited on unpatched PAN-OS devices. Rapid7 says it saw successful attacks in multiple customer environments, with some cases leading to VPN access inside the network.

Why it matters

This is an internet-facing VPN flaw, which makes it a direct path into enterprise networks. Active exploitation means defenders need to patch or mitigate quickly, not wait for later confirmation of impact.

A door meant for workers had a weak lock trick. Some attackers found a way to slip past the check and pretend they were allowed in.

That matters because the door is not inside the building. It sits at the front, where the whole company can be reached.

The fix is to patch it fast or turn off the tricky feature for now, like changing a broken lock before more people test it.

Analysis

What happened

Palo Alto Networks says CVE-2026-0257 affects PAN-OS and Prisma Access when GlobalProtect portal or gateway is configured with authentication override cookies and a specific certificate setup. The flaw lets an attacker bypass authentication and establish an unauthorized VPN connection.

Evidence of exploitation

In an update on May 29, 2026, Palo Alto said it had become aware of limited exploit attempts against unpatched devices without mitigations. Rapid7 reported successful exploitation across multiple customers, with the earliest activity dated May 17 and a second wave on May 21. Rapid7 said both waves appear to come from the same threat actor. In two cases, the second wave led to VPN IP assignment after cookie authentication, which gave the attacker access to the internal network. Rapid7 said it saw no follow-on activity in those environments where a VPN session was established.

Defender response

Palo Alto described the bug as medium severity with a CVSS score of 7.8, but the article makes clear that the real risk is exposure of edge-facing enterprise VPN appliances. The recommended response is urgent patching. As temporary mitigations, organizations can disable the authentication override feature or generate a new certificate used only for that feature.

The article also frames this in a broader pattern of active exploitation against perimeter products, noting another report about weaponized FortiClient EMS flaws being used to deliver credential-stealing malware.

Key points

  • Palo Alto Networks says CVE-2026-0257 allows authentication bypass in GlobalProtect portal and gateway setups.
  • The company says the flaw is being exploited on unpatched PAN-OS devices without mitigations.
  • Rapid7 reported successful exploitation at multiple customers, with activity starting May 17 and a second wave on May 21, 2026.
  • In two cases, the attack led to VPN IP assignment and internal network access.
  • Recommended mitigations are patching urgently, disabling authentication override, or using a new certificate for that feature.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritytechvulnerabilitynetwork-securityvpnpalo-alto-networks

Author

Ravie Lakshmanan

Intelligence analysis by

GPT-5.4 Mini

Published

May 30, 2026

Source

thehackernews.com

Share

Topics

securitytechvulnerabilitynetwork-securityvpnpalo-alto-networks

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…