Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

PAN-OS GlobalProtect Authentication Bypass under Active Exploit (CVE-2026-0257)

ChatGPhish vulnerability turns ChatGPT web summaries into phishing surfaces

AI chip startup Groq reportedly raises $650 million after Nvidia’s $20 billion non-acquisition

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » PAN-OS GlobalProtect Authentication Bypass under Active Exploit (CVE-2026-0257)
Identity

PAN-OS GlobalProtect Authentication Bypass under Active Exploit (CVE-2026-0257)

By May 30, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Rabi LakshmananMay 30, 2026Vulnerability/Network Security

Palo Alto Networks has warned that a medium-severity security flaw affecting PAN-OS and Prisma Access has recently been disclosed and is being exploited in the wild.

This vulnerability is tracked as CVE-2026-0257 (CVSS score: 7.8) and refers to a case of authentication bypass that can be exploited by a malicious attacker to set up a VPN connection.

“An authentication bypass vulnerability in the GlobalProtect Portal and Gateway in Palo Alto Networks PAN-OS® software could allow an attacker to bypass security restrictions and establish unauthorized VPN connections,” Palo Alto Networks said in an advisory released on May 13, 2026.

The network security company said this issue specifically affects firewalls on which the GlobalProtect portal or gateway is configured when authentication override cookies are enabled and certain certificate configurations are present.

In a May 29, 2026 advisory update, Palo Alto Networks said it was “aware of limited exploitation attempts against unmitigated and unpatched PAN-OS devices.”

The development comes after Rapid7 revealed it had identified a successful exploit across a number of customers, with the first effort dating back to May 17, 2026, followed by a second wave on May 21. Both sets of exploits are believed to be the work of the same threat actor.

Activity observed in the second wave included cookie authentication followed by VPN IP assignment in two cases, granting attackers access to internal networks. The cybersecurity vendor added that no further activity occurred in the customer environment where the VPN session was established.

“Authentication bypass on edge-facing enterprise VPN appliances can have a significant impact on affected organizations,” Rapid7 said. “As a result, organizations running affected appliances are urged to urgently upgrade to vendor-provided patches.”

As a temporary mitigation, we recommend that you disable the Authentication Override feature or generate a new certificate to use specifically for the Authentication Override feature.

The exploitation of CVE-2026-0257 follows Arctic Wolf’s reporting that a critical security flaw affecting FortiClient Endpoint Management Server (EMS) deployments (CVE-2026-35616, CVSS score: 9.1) continues to be weaponized and now patched to deliver credential-stealing malware known as EKZ Infostealer.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleChatGPhish vulnerability turns ChatGPT web summaries into phishing surfaces

Related Posts

ChatGPhish vulnerability turns ChatGPT web summaries into phishing surfaces

May 29, 2026

Marimo CVE-2026-39987 After exploitation, attacker uses LLM agent for post-exploitation purposes

May 29, 2026

New Russian-linked GREYVIBE targets Ukraine with AI-powered cyber attack

May 29, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

PAN-OS GlobalProtect Authentication Bypass under Active Exploit (CVE-2026-0257)

ChatGPhish vulnerability turns ChatGPT web summaries into phishing surfaces

AI chip startup Groq reportedly raises $650 million after Nvidia’s $20 billion non-acquisition

Microsoft accused of threatening security researchers with criminal investigation

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.