Palo Alto Networks confirmed that hackers are actively exploiting a medium-severity security flaw in its PAN-OS software. The vulnerability, identified as CVE-2026-0257, allows an authentication bypass on firewalls using GlobalProtect portals or gateways. Successful exploitation enables unauthorized attackers to establish VPN connections and bypass security restrictions.
The company issued an initial advisory on May 13, 2026. A follow-up on May 29, 2026, reported limited exploit attempts on unpatched devices lacking mitigations. The issue specifically targets configurations where authentication override cookies are enabled with a specific certificate setup.
Security firm Rapid7 reported successful exploitations across multiple customer accounts. The earliest detected exploit attempts occurred on May 17, 2026.