CVE-2026-0257Active Exploitation(paloaltonetworks / pan-os)

CRITICALCVSS 9.1 · CRITICALCISA KEV

Exploitation observed; activity peaked at 59 mentions and remains active

Immediate actions

  • Patch paloaltonetworks pan-os systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

10.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-06-01. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-565

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pan-os
  • prisma_access
  • ruggedcom_ape1808
  • ruggedcom_ape1808_firmware

Threat summary

  • Active exploitation appears in 372 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 441 mentions across 54 observed days

What's happening

  • Active exploitation reported across 372 signals
  • Exploit tool or code specified in 24 signals
  • PoC mentioned or linked in 37 signals
  • Patch or workaround mentioned in 136 signals
  • Technical details provided in 291 signals
  • General: 29 classified signals
  • Disclosure: 20 classified signals
  • Peaked 47d ago at 59 mentions (2026-06-01); latest day: 2
  • 441 total mentions across 54 days

Affected systems

Products
pan-osprisma_accessruggedcom_ape1808ruggedcom_ape1808_firmware

45 versions affected across 4 products

Deep dive

Activity timeline441 mentions / 54d
015304459Mentions · 2026-05-13: 2Mentions · 2026-05-14: 1Mentions · 2026-05-21: 1Mentions · 2026-05-29: 15Mentions · 2026-05-30: 56Mentions · 2026-05-31: 46Mentions · 2026-06-01: 59Mentions · 2026-06-02: 39Mentions · 2026-06-03: 17Mentions · 2026-06-04: 4Mentions · 2026-06-05: 10Mentions · 2026-06-06: 9Mentions · 2026-06-07: 3Mentions · 2026-06-08: 10Mentions · 2026-06-09: 1Mentions · 2026-06-10: 6Mentions · 2026-06-11: 3Mentions · 2026-06-12: 2Mentions · 2026-06-14: 1Mentions · 2026-06-15: 38Mentions · 2026-06-16: 7Mentions · 2026-06-17: 1Mentions · 2026-06-18: 4Mentions · 2026-06-19: 1Mentions · 2026-06-20: 3Mentions · 2026-06-22: 5Mentions · 2026-06-23: 1Mentions · 2026-06-27: 1Mentions · 2026-06-30: 1Mentions · 2026-07-08: 2Mentions · 2026-07-10: 2Mentions · 2026-07-20: 2Mentions · 2026-07-21: 35Mentions · 2026-07-22: 14Mentions · 2026-07-23: 4Mentions · 2026-07-25: 3Mentions · 2026-07-26: 1Mentions · 2026-07-27: 3Mentions · 2026-07-28: 1Mentions · 2026-07-29: 1Mentions · 2026-07-31: 2Mentions · 2026-08-06: 1Mentions · 2026-08-10: 1Mentions · 2026-09-01: 1Mentions · 2026-09-07: 1Mentions · 2026-09-08: 1Mentions · 2026-09-11: 4Mentions · 2026-09-12: 5Mentions · 2026-09-19: 1Mentions · 2026-09-24: 2Mentions · 2026-09-25: 2Mentions · 2026-09-28: 2Mentions · 2026-09-30: 1Mentions · 2026-10-08: 2PoC Mentioned / Linked · 2026-05-29: 1PoC Mentioned / Linked · 2026-05-30: 7PoC Mentioned / Linked · 2026-05-31: 5PoC Mentioned / Linked · 2026-06-01: 5PoC Mentioned / Linked · 2026-06-02: 2PoC Mentioned / Linked · 2026-06-04: 1PoC Mentioned / Linked · 2026-06-06: 1PoC Mentioned / Linked · 2026-06-12: 1PoC Mentioned / Linked · 2026-06-15: 3PoC Mentioned / Linked · 2026-06-20: 1PoC Mentioned / Linked · 2026-06-22: 1PoC Mentioned / Linked · 2026-07-08: 1PoC Mentioned / Linked · 2026-07-20: 1PoC Mentioned / Linked · 2026-07-22: 1PoC Mentioned / Linked · 2026-07-23: 1PoC Mentioned / Linked · 2026-07-27: 1PoC Mentioned / Linked · 2026-07-29: 1PoC Mentioned / Linked · 2026-07-31: 1PoC Mentioned / Linked · 2026-09-01: 1PoC Mentioned / Linked · 2026-09-12: 1Exploit Tool / Code · 2026-05-29: 1Exploit Tool / Code · 2026-05-31: 8Exploit Tool / Code · 2026-06-01: 3Exploit Tool / Code · 2026-06-04: 1Exploit Tool / Code · 2026-06-12: 1Exploit Tool / Code · 2026-06-15: 1Exploit Tool / Code · 2026-07-08: 1Exploit Tool / Code · 2026-07-20: 1Exploit Tool / Code · 2026-07-21: 4Exploit Tool / Code · 2026-07-27: 1Exploit Tool / Code · 2026-09-01: 1Exploit Tool / Code · 2026-09-25: 1Active Exploitation · 2026-05-29: 12Active Exploitation · 2026-05-30: 46Active Exploitation · 2026-05-31: 43Active Exploitation · 2026-06-01: 53Active Exploitation · 2026-06-02: 33Active Exploitation · 2026-06-03: 13Active Exploitation · 2026-06-04: 3Active Exploitation · 2026-06-05: 8Active Exploitation · 2026-06-06: 7Active Exploitation · 2026-06-07: 3Active Exploitation · 2026-06-08: 10Active Exploitation · 2026-06-09: 1Active Exploitation · 2026-06-10: 5Active Exploitation · 2026-06-11: 3Active Exploitation · 2026-06-12: 2Active Exploitation · 2026-06-14: 1Active Exploitation · 2026-06-15: 37Active Exploitation · 2026-06-16: 6Active Exploitation · 2026-06-17: 1Active Exploitation · 2026-06-18: 3Active Exploitation · 2026-06-19: 1Active Exploitation · 2026-06-20: 3Active Exploitation · 2026-06-22: 3Active Exploitation · 2026-06-23: 1Active Exploitation · 2026-06-27: 1Active Exploitation · 2026-07-08: 1Active Exploitation · 2026-07-10: 2Active Exploitation · 2026-07-20: 1Active Exploitation · 2026-07-21: 32Active Exploitation · 2026-07-22: 13Active Exploitation · 2026-07-23: 4Active Exploitation · 2026-07-25: 2Active Exploitation · 2026-07-26: 1Active Exploitation · 2026-07-27: 2Active Exploitation · 2026-07-28: 1Active Exploitation · 2026-07-31: 2Active Exploitation · 2026-08-06: 1Active Exploitation · 2026-08-10: 1Active Exploitation · 2026-09-07: 1Active Exploitation · 2026-09-08: 1Active Exploitation · 2026-09-11: 1Active Exploitation · 2026-09-12: 2Active Exploitation · 2026-09-19: 1Active Exploitation · 2026-09-24: 1Active Exploitation · 2026-09-25: 2Active Exploitation · 2026-09-28: 1Patch / Workaround · 2026-05-29: 5Patch / Workaround · 2026-05-30: 13Patch / Workaround · 2026-05-31: 17Patch / Workaround · 2026-06-01: 15Patch / Workaround · 2026-06-02: 14Patch / Workaround · 2026-06-03: 7Patch / Workaround · 2026-06-05: 4Patch / Workaround · 2026-06-06: 1Patch / Workaround · 2026-06-07: 2Patch / Workaround · 2026-06-08: 3Patch / Workaround · 2026-06-09: 1Patch / Workaround · 2026-06-10: 4Patch / Workaround · 2026-06-11: 1Patch / Workaround · 2026-06-15: 12Patch / Workaround · 2026-06-16: 2Patch / Workaround · 2026-06-17: 1Patch / Workaround · 2026-06-18: 1Patch / Workaround · 2026-06-22: 2Patch / Workaround · 2026-06-23: 1Patch / Workaround · 2026-06-27: 1Patch / Workaround · 2026-06-30: 1Patch / Workaround · 2026-07-08: 1Patch / Workaround · 2026-07-21: 11Patch / Workaround · 2026-07-22: 2Patch / Workaround · 2026-07-23: 2Patch / Workaround · 2026-07-25: 2Patch / Workaround · 2026-07-26: 1Patch / Workaround · 2026-07-27: 3Patch / Workaround · 2026-07-28: 1Patch / Workaround · 2026-07-31: 2Patch / Workaround · 2026-09-07: 1Patch / Workaround · 2026-09-12: 1Patch / Workaround · 2026-09-24: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-29: 14Technical Details · 2026-05-30: 39Technical Details · 2026-05-31: 31Technical Details · 2026-06-01: 39Technical Details · 2026-06-02: 27Technical Details · 2026-06-03: 11Technical Details · 2026-06-04: 2Technical Details · 2026-06-05: 7Technical Details · 2026-06-06: 5Technical Details · 2026-06-07: 2Technical Details · 2026-06-08: 8Technical Details · 2026-06-09: 1Technical Details · 2026-06-10: 4Technical Details · 2026-06-11: 2Technical Details · 2026-06-12: 2Technical Details · 2026-06-15: 26Technical Details · 2026-06-16: 4Technical Details · 2026-06-18: 2Technical Details · 2026-06-22: 5Technical Details · 2026-06-23: 1Technical Details · 2026-06-27: 1Technical Details · 2026-06-30: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-10: 2Technical Details · 2026-07-20: 1Technical Details · 2026-07-21: 21Technical Details · 2026-07-22: 7Technical Details · 2026-07-23: 2Technical Details · 2026-07-25: 2Technical Details · 2026-07-26: 1Technical Details · 2026-07-27: 2Technical Details · 2026-07-28: 1Technical Details · 2026-07-29: 1Technical Details · 2026-07-31: 2Technical Details · 2026-08-06: 1Technical Details · 2026-09-08: 1Technical Details · 2026-09-11: 1Technical Details · 2026-09-12: 4Technical Details · 2026-09-19: 1Technical Details · 2026-09-24: 1Technical Details · 2026-09-25: 2Technical Details · 2026-09-28: 105-1305-3106-0506-1006-1606-2207-1007-2507-3109-0809-2510-08
Signal classification6 categories
Active Exploitation
36383.1%
General
296.6%
Disclosure
204.6%
Patch
143.2%
Exploit
61.4%
PoC
51.1%
Referenced assets285 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-132
Disclosure1General1
2026-05-141
Disclosure1
2026-05-211
General1
2026-05-2915
Active Exploitation12Disclosure2General1
2026-05-3056
Active Exploitation46Disclosure2General7Patch1
2026-05-3146
Active Exploitation41Disclosure2Exploit1General1Patch1
2026-06-0159
Active Exploitation53Disclosure1General3Patch1PoC1
2026-06-0239
Active Exploitation32Exploit1General2Patch3PoC1
2026-06-0317
Active Exploitation13General4
2026-06-044
Active Exploitation3PoC1
2026-06-0510
Active Exploitation8General1Patch1
2026-06-069
Active Exploitation7Disclosure2
2026-06-073
Active Exploitation3
2026-06-0810
Active Exploitation10
2026-06-091
Active Exploitation1
2026-06-106
Active Exploitation4Patch2
2026-06-113
Active Exploitation2Patch1
2026-06-122
Active Exploitation2
2026-06-141
Active Exploitation1
2026-06-1538
Active Exploitation37Exploit1
2026-06-167
Active Exploitation6Disclosure1
2026-06-171
Active Exploitation1
2026-06-184
Active Exploitation3General1
2026-06-191
Active Exploitation1
2026-06-203
Active Exploitation3
2026-06-225
Active Exploitation2Disclosure2Exploit1
2026-06-231
Active Exploitation1
2026-06-271
Active Exploitation1
2026-06-301
Patch1
2026-07-082
Active Exploitation1PoC1
2026-07-102
Active Exploitation2
2026-07-202
Exploit1General1
2026-07-2135
Active Exploitation32Disclosure1General2
2026-07-2214
Active Exploitation13Disclosure1
2026-07-234
Active Exploitation4
2026-07-253
Active Exploitation1Disclosure1Patch1
2026-07-261
Active Exploitation1
2026-07-273
Active Exploitation2Disclosure1
2026-07-281
Active Exploitation1
2026-07-291
PoC1
2026-07-312
Active Exploitation1Patch1
2026-08-061
Active Exploitation1
2026-08-101
Active Exploitation1
2026-09-011
Exploit1
2026-09-071
Active Exploitation1
2026-09-081
Active Exploitation1
2026-09-114
Active Exploitation1Disclosure1General2
2026-09-125
Active Exploitation2Disclosure1General2
2026-09-191
Active Exploitation1
2026-09-242
Active Exploitation1Patch1
2026-09-252
Active Exploitation2
2026-09-282
Active Exploitation1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 Hackers found a way into Palo Alto’s GlobalProtect VPN without a password. The flaw, tracked as CVE-2026-0257, lets attackers bypass PAN-OS authentication and establish unauthorized VPN sessions. Palo Alto says it’s already being used in real attacks. If you run GlobalProtect, check this now. Details ➝ https://thehackernews.com/2026/06/palo-alto-warns-of-active-exploitation.html

    Post summary

    CVE-2026-0257 allows bypassing PAN‑OS authentication for unauthorized VPN sessions, and Palo Alto reports it is already actively exploited.

    22287341.1K375166.6K
    2.2M followersView on X
  • Nathan McNulty@NathanMcNulty
    General

    CVE-2020-2033, CVE-2020-2021, CVE-2020-2050, CVE-2026-0257, and now CVE-2026-0265 Authentication bypass, as in direct access to your internal networks over the Internet This VPN architecture should be dead, get it off the Internet, it's a time bomb waiting to happen

    Post summary

    The post cites several CVEs that allegedly allow authentication bypass for VPNs and warns that the VPN architecture is unsafe, but offers no technical depth, exploit code, or remediation details.

    4596452212113.6K
    18.5K followersView on X
  • Dhiyaneshwaran@DhiyaneshDK
    Active Exploitation

    🚨 CVE-2026-0257- Palo Alto Networks PAN-OS - Authentication Bypass 🔍 Nuclei Template: https://cloud.projectdiscovery.io/library/CVE-2026-0257 📑 Reference: https://www.rapid7.com/blog/post/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257/ #kev #authbypass #bugbounty https://t.co/GGXI5iEZvo

    Post summary

    The tweet highlights CVE-2026-0257, an authentication bypass in Palo Alto PAN-OS, noting active exploitation observed by Rapid7 and providing a Nuclei PoC template for detection.

    475033620723.9K
    4.5K followersView on X
  • Pirat_Nation 🔴@Pirat_Nation
    Active Exploitation

    Palo Alto Networks says attackers are actively exploiting a GlobalProtect VPN vulnerability known as CVE-2026-0257. The bug affects certain GlobalProtect portal and gateway setups and lets attackers connect to a VPN without the usual login and authentication checks. Since GlobalProtect is typically exposed to the internet, a successful attack could give cybercriminals access to an organization’s internal network. Security researchers have already observed real-world attacks targeting vulnerable systems. If your organization uses GlobalProtect, check whether you are affected and install the latest security updates. Palo Alto Networks has released fixes for supported PAN-OS versions and urges customers to update as soon as possible. Security teams should also monitor VPN logs and investigate any unusual login activity or unexpected VPN connections.

    Post summary

    Palo Alto Networks reports that CVE‑2026‑0257 is being actively exploited to bypass GlobalProtect VPN authentication, and patches have been released—customers should update immediately and monitor logs.

    93702643818.3K
    339.2K followersView on X
  • Cyber Security News@The_Cyber_News
    Active Exploitation

    🚨 Palo Alto Warns of GlobalProtect VPN Vulnerability Actively Exploited in the Wild Source: https://cybersecuritynews.com/palo-alto-vpn-vulnerability-exploited/ Palo Alto Networks Unit 42 has issued an urgent warning about active exploitation of CVE-2026-0257, a critical authentication bypass vulnerability affecting the GlobalProtect portal and gateway components of PAN-OS software. The flaw allows unauthenticated remote attackers to circumvent security controls and initiate unauthorized VPN connections without requiring any credentials. Organizations are urged to immediately hunt for indicators of compromise (IOCs) in their GlobalProtect logs and activate incident response protocols for any successful gateway-connected events tied to the listed indicators. #cybersecuritynews

    Post summary

    Palo Alto warns that CVE-2026-0257, a critical authentication bypass in GlobalProtect, is being actively exploited in the wild, urging organizations to investigate and respond.

    15242113714.3K
    70.7K followersView on X
  • Cyber Security News@The_Cyber_News
    Active Exploitation

    ❗️❗️Threat actors are actively exploiting a critical authentication bypass flaw in Palo Alto Networks firewalls to breach corporate networks and deploy Qilin ransomware. Full Story: https://cybersecuritynews.com/cve-2026-0257-qilin-ransomware/ The flaw, tracked as CVE-2026-0257 (CVSS 7.8), affects the GlobalProtect portal and gateway in PAN-OS. It becomes exploitable when authentication override cookies are enabled alongside specific certificate configurations, allowing unauthenticated attackers to bypass login controls entirely and establish legitimate-looking VPN sessions. #cybersecuritynews

    Post summary

    CVE‑2026‑0257 is actively exploited by threat actors to bypass authentication on Palo Alto Networks firewalls and deploy Qilin ransomware. The passage provides technical details of the flaw but does not mention any PoC, exploit code, or patch information.

    64711686433.6K
    72.9K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 CVE-2026-0257, a PAN-OS and Prisma Access authentication bypass flaw, is under active exploitation. The CVSS 7.8 bug can enable unauthorized VPN access and, in some observed cases, access to internal networks. Patch immediately or apply mitigations. Details: https://thehackernews.com/2026/05/pan-os-globalprotect-authentication.html

    Post summary

    CVE‑2026‑0257 is an authentication bypass flaw in PAN‑OS and Prisma Access currently exploited in the wild, with a CVSS score of 7.8, necessitating immediate patching or mitigations.

    45041542343.2K
    1.9M followersView on X
  • Cyber Security News@The_Cyber_News
    Active Exploitation

    🚨 Palo Alto Networks PAN-OS Authentication Vulnerability Bypass Exploited in the Wild Source: https://cybersecuritynews.com/palo-alto-vulnerability-exploited/ Palo Alto Networks authentication bypass vulnerability, CVE-2026-0257, affecting PAN-OS and Prisma Access, is now being actively exploited in the wild, with CISA adding it to the Known Exploited Vulnerabilities (KEV) catalog on May 29, 2026. The vulnerability exists in a non-default feature called "authentication override," which allows GlobalProtect portals and gateways to issue session cookies to authenticated users similar to a bearer token, so users don't need to re-authenticate each session. The flaw is triggered only when the certificate used to encrypt and decrypt these authentication override cookies is shared with another feature, such as the HTTPS service of the portal or gateway. #cybersecuritynews #vulnerability

    Post summary

    The text reports that CVE-2026-0257 is actively exploited in the wild, with technical details of the vulnerability but no mention of PoC, exploit code, patch, or false‑positive claims.

    1331122308.1K
    68.9K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 Attackers are exploiting Palo Alto Networks PAN-OS flaw CVE-2026-0257 to deploy Qilin ransomware. Some intrusions ended in rapid encryption. Others escalated to credential theft, data exfiltration, and double extortion. How the attacks unfolded: https://thehackernews.com/2026/07/qilin-ransomware-attackers-exploit-pan.html

    Post summary

    Attackers are actively exploiting CVE-2026-0257 in Palo Alto Networks PAN-OS, deploying Qilin ransomware that leads to encryption, credential theft, data exfiltration, and double extortion.

    03311022539.3K
    2.3M followersView on X
  • Stephen Fewer@stephenfewer
    Active Exploitation

    New @rapid7 observed exploitation of PAN-OS GlobalProtect auth bypass vulnerability CVE-2026-0257 which allows authentication bypass cookies to be forged for VPN access. Full details, technical analysis, PoC , IOCs and remediation guidance in the blog: https://www.rapid7.com/blog/post/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257/

    Post summary

    Rapid7 reported real‑world exploitation of PAN‑OS GlobalProtect auth bypass CVE-2026-0257, including PoC details and remediation guidance.

    1221933410.2K
    9.8K followersView on X
  • 嶋田大貴@shimarin
    General

    CVE-2026-0257、公表当初はCVSS4.7だけど実害観測が出て後から7.8に引き上がったのか。機器の詳細設定を把握している人がCVEの内容まで精査していたら気付けたかもしれないとはいえ、デジ庁のがこれだとしたら担当者を責めるのは酷な気がするな。

    Post summary

    The post comments on a CVE’s CVSS score evolution, noting an increase from 4.7 to 7.8, without mentioning any PoC, exploit, patch, or active exploitation.

    520285299.8K
    4.6K followersView on X
  • Defused@DefusedCyber
    Active Exploitation

    🚨 Based on @rapid7 observations of exploitation of PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257), we can also confirm first signs of exploitation around the same time (May 18th on the Defused TF feeds, and a customer hit on May 17th) The exploit payload differs slightly from Rapid 7's POC with the user-agent PAN GlobalProtect/6.0.0 Attacker IP: 104.207.144[.]154 🇺🇸 AS20473 The Constant Company Rapid7 write-up: https://www.rapid7.com/blog/post/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257/

    Post summary

    Rapid7 confirmed in‑the‑wild exploitation of CVE-2026-0257, noting an attacker IP, a slightly altered payload, and early attack indicators from May 17‑18.

    0191642313.2K
    7.5K followersView on X
  • ボス@サイバーセキュリティの専門家@boss_sec_labo
    Active Exploitation

    SuicaのICチップが狙われ、自宅のIoT機器が不正送金の踏み台にされ、AIが攻撃者の武器になった。 VPNは突破され、1354万件の記録が紛失した。 今日の8件は、どれもひとごとではない。 ・FeliCa ICチップCVE-2026-59776、Suica・PASMO読み取り改ざんの恐れ ・家庭用IoT数万台が不正送金事件の踏み台に、NICT・総務省・警察庁が公表 ・GlobalProtect VPN CVE-2026-0257、Qilinランサムがネットワーク侵入に積極悪用 ・九州電力送配電SSD紛失、顧客情報最大1354万件の漏洩懸念 ・ServiceNow CVE-2026-6875、未認証RCEが公開数日で野外悪用 ・Hugging Face CEO警告、攻撃者はすでにAIエージェントを実攻撃に使っている ・DrupalのAIプラグインにCVSS7.1の認証不備、アカウント乗っ取りの恐れ ・MetaサポートAPIの認証不備、顧客情報アクセス可能で78,000ドルのバウンティ 今日の8件に共通する入り口は、普通の機器と普通の設定だった。 Suicaのチップ、自宅のルーター、VPN、AIプラグイン。 君の現場の「普通」は、まだ安全か?

    Post summary

    The report lists eight CVEs, several of which—such as ServiceNow CVE‑2026‑6875 and GlobalProtect VPN CVE‑2026‑0257—are already being actively exploited in the wild, with detailed vulnerability information but no mention of patches or PoCs.

    010161335.4K
    1.6K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Active Exploitation

    🚨 تحذير الجهات الي تستخدم (Palo Alto GlobalProtect VPN) حدثوه الان في ثغرة صدرت بتاريخ 13/5/2026 رقمها (CVE-2026-0257) في نظام (PAN-OS) الثغره تسمح بتجاوز المصادقة وإنشاء اتصال (VPN) غير مصرح به بدون كلمة مرور، وتُستغل الآن من قبل المخترقين. ـCISA أضافتها لقائمة (KEV) https://t.co/GRTz4r4CTa

    Post summary

    CVE-2026-0257 enables unauthenticated VPN connections on Palo Alto PAN-OS and is currently being exploited by hackers, prompting CISA to add it to the KEV list.

    19054326.1K
    50.0K followersView on X
  • CISA Cyber@CISACyber
    Disclosure

    🛡️ We added Palo Alto Networks PAN-OS authentication bypass vulnerability CVE-2026-0257 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q for more information. #Cybersecurity #InfoSec https://t.co/iqNABP4rQ9

    Post summary

    The tweet announces that the PAN-OS authentication bypass vulnerability CVE-2026-0257 has been added to the DHS KEV catalog, but it does not provide details on PoC, exploitation, patches, or active attacks.

    521054119.5K
    300.1K followersView on X
  • FOFA@fofabot
    Active Exploitation

    ⚠️⚠️ CVE-2026-0257 (CVSS 9.1): GlobalProtect auth bypass; active exploitation (CISA KEV) 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJwYWxvYWx0by1HbG9iYWxQcm90ZWN0Ig== 🎯1.1M+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="paloalto-GlobalProtect" 🔖Refer: https://www.rapid7.com/blog/post/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257/ #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    CISA reports active exploitation of Palo Alto’s GlobalProtect authentication bypass (CVE-2026-0257) with a CVSS score of 9.1, yet no patch or PoC is disclosed.

    010051204.7K
    14.4K followersView on X
  • elhacker.NET@elhackernet
    Active Exploitation

    Explotación activa de vulnerabilidad de bypass de autenticación en PAN-OS GlobalProtect (CVE-2026-0257) https://blog.elhacker.net/2026/05/explotacion-activa-de-vulnerabilidad-de.html

    Post summary

    The blog post announces that the authentication bypass vulnerability CVE‑2026‑0257 in PAN‑OS GlobalProtect is being actively exploited in the wild.

    112049114.0K
    140.9K followersView on X
  • OccupytheWeb@three_cube
    Active Exploitation

    Still Another VPN being compromised by attackers! 😤 And you thought your VPN was keeping you safe 😅 https://www.rapid7.com/blog/post/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257/

    Post summary

    The Rapid7 Blog post reports that CVE‑2026‑0257, an authentication bypass vulnerability in PAN‑OS GlobalProtect, is being actively exploited in the wild.

    011050124.3K
    265.2K followersView on X
  • mRr3b00t@UK_Daniel_Card
    Active Exploitation

    I'm doing some analysis against the honeypots in @DefusedCyber and Claude came out with this.... (in the screenshot) https://www.rapid7.com/blog/post/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257/ https://t.co/ShLJR73IL0

    Post summary

    The tweet points to a Rapid7 report describing in‑the‑wild exploitation of CVE‑2026‑0257 against Palo Alto Networks GlobalProtect; no PoC, exploit code, patch, or false‑positive claim is referenced.

    33049145.8K
    124.6K followersView on X
  • connect24h@connect24h
    Active Exploitation

    GSSへの不正アクセス、時系列で見るとどこら辺から危なかったが可視化されますね。5/29が一つの分水嶺ですね。 5/13 CVE-2026-0257公開 当初CVSS 4.7「Medium」 5/17 Rapid7が実悪用を観測 5月下旬 GSSへの侵入が始まったとみられる 5/29 CISA KEV登録 CVSS 7.8へ 公開PoCも出現 つまり、 PoCが出てから攻撃されたのではない。 実悪用はPoC公開より先。 6/25 GSSで保守運用アカウントによる 大量ファイルアクセスを検知 7/9 VPN機器の脆弱性を利用した侵入と判明 アカウント停止、通信遮断、パッチ適用 9/11 デジタル庁が公表 漏えい可能性は約24.6万件。 ここで怖いのは 「PoCが出たら危険」ではない。 攻撃者は、 PoCが公開される前から動いている。 CVSS、PoC、KEVを待ってから優先順位を変えるのでは遅い。 Internet Facingか。 認証境界か。 侵害後にどこまで到達できるか。 そこまで見て、 脆弱性の優先順位を決める必要がある。 ※GSSで悪用されたVPN製品・CVE番号は非公表。CVE-2026-0257との関連は公開情報からの推測。 https://bs-square.jp/blog/index.php/2026/06/10/palo-alto-networks-globalprotect-authentication-bypass-what-security-teams-should-know-about-cve-2026-0257/

    Post summary

    The post chronicles real-world exploitation of CVE‑2026‑0257, noting that attackers were active before a public PoC appeared, and includes references to patches and vulnerability details.

    22035253.5K
    8.5K followersView on X
CPE platform detail163 entries

163 of 163 entries

PartVendorProductVersionTarget SWTarget HW
OSpaloaltonetworkspan-os---
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.10--
OSpaloaltonetworkspan-os10.2.11--
OSpaloaltonetworkspan-os10.2.12--
OSpaloaltonetworkspan-os10.2.13--
OSpaloaltonetworkspan-os10.2.13--
OSpaloaltonetworkspan-os10.2.13--
OSpaloaltonetworkspan-os10.2.13--
OSpaloaltonetworkspan-os10.2.13--
OSpaloaltonetworkspan-os10.2.13--
OSpaloaltonetworkspan-os10.2.13--
OSpaloaltonetworkspan-os10.2.13--
OSpaloaltonetworkspan-os10.2.13--
OSpaloaltonetworkspan-os10.2.13--
OSpaloaltonetworkspan-os10.2.14--
OSpaloaltonetworkspan-os10.2.15--
OSpaloaltonetworkspan-os10.2.16--
OSpaloaltonetworkspan-os10.2.16--
OSpaloaltonetworkspan-os10.2.16--
OSpaloaltonetworkspan-os10.2.16--
OSpaloaltonetworkspan-os10.2.17--
OSpaloaltonetworkspan-os10.2.18--
OSpaloaltonetworkspan-os10.2.18--
OSpaloaltonetworkspan-os10.2.18--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.7--
OSpaloaltonetworkspan-os10.2.8--
OSpaloaltonetworkspan-os10.2.9--
OSpaloaltonetworkspan-os11.1.0--
OSpaloaltonetworkspan-os11.1.1--
OSpaloaltonetworkspan-os11.1.10--
OSpaloaltonetworkspan-os11.1.10--
OSpaloaltonetworkspan-os11.1.10--
OSpaloaltonetworkspan-os11.1.10--
OSpaloaltonetworkspan-os11.1.10--
OSpaloaltonetworkspan-os11.1.10--
OSpaloaltonetworkspan-os11.1.10--
OSpaloaltonetworkspan-os11.1.10--
OSpaloaltonetworkspan-os11.1.10--
OSpaloaltonetworkspan-os11.1.11--
OSpaloaltonetworkspan-os11.1.12--
OSpaloaltonetworkspan-os11.1.13--
OSpaloaltonetworkspan-os11.1.13--
OSpaloaltonetworkspan-os11.1.13--
OSpaloaltonetworkspan-os11.1.13--
OSpaloaltonetworkspan-os11.1.14--
OSpaloaltonetworkspan-os11.1.2--
OSpaloaltonetworkspan-os11.1.3--
OSpaloaltonetworkspan-os11.1.4--
OSpaloaltonetworkspan-os11.1.4--
OSpaloaltonetworkspan-os11.1.4--
OSpaloaltonetworkspan-os11.1.4--
OSpaloaltonetworkspan-os11.1.4--
OSpaloaltonetworkspan-os11.1.4--
OSpaloaltonetworkspan-os11.1.4--
OSpaloaltonetworkspan-os11.1.4--
OSpaloaltonetworkspan-os11.1.4--
OSpaloaltonetworkspan-os11.1.4--
OSpaloaltonetworkspan-os11.1.4--
OSpaloaltonetworkspan-os11.1.4--
OSpaloaltonetworkspan-os11.1.4--
OSpaloaltonetworkspan-os11.1.5--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.6--
OSpaloaltonetworkspan-os11.1.7--
OSpaloaltonetworkspan-os11.1.7--
OSpaloaltonetworkspan-os11.1.7--
OSpaloaltonetworkspan-os11.1.7--
OSpaloaltonetworkspan-os11.1.8--
OSpaloaltonetworkspan-os11.1.9--
OSpaloaltonetworkspan-os11.2.0--
OSpaloaltonetworkspan-os11.2.1--
OSpaloaltonetworkspan-os11.2.10--
OSpaloaltonetworkspan-os11.2.10--
OSpaloaltonetworkspan-os11.2.10--
OSpaloaltonetworkspan-os11.2.10--
OSpaloaltonetworkspan-os11.2.10--
OSpaloaltonetworkspan-os11.2.10--
OSpaloaltonetworkspan-os11.2.10--
OSpaloaltonetworkspan-os11.2.11--
OSpaloaltonetworkspan-os11.2.2--
OSpaloaltonetworkspan-os11.2.3--
OSpaloaltonetworkspan-os11.2.4--
OSpaloaltonetworkspan-os11.2.4--
OSpaloaltonetworkspan-os11.2.4--
OSpaloaltonetworkspan-os11.2.4--
OSpaloaltonetworkspan-os11.2.4--
OSpaloaltonetworkspan-os11.2.4--
OSpaloaltonetworkspan-os11.2.4--
OSpaloaltonetworkspan-os11.2.4--
OSpaloaltonetworkspan-os11.2.4--
OSpaloaltonetworkspan-os11.2.4--
OSpaloaltonetworkspan-os11.2.4--
OSpaloaltonetworkspan-os11.2.4--
OSpaloaltonetworkspan-os11.2.4--
OSpaloaltonetworkspan-os11.2.4--
OSpaloaltonetworkspan-os11.2.5--
OSpaloaltonetworkspan-os11.2.6--
OSpaloaltonetworkspan-os11.2.7--
OSpaloaltonetworkspan-os11.2.7--
OSpaloaltonetworkspan-os11.2.7--
OSpaloaltonetworkspan-os11.2.7--
OSpaloaltonetworkspan-os11.2.7--
OSpaloaltonetworkspan-os11.2.7--
OSpaloaltonetworkspan-os11.2.7--
OSpaloaltonetworkspan-os11.2.7--
OSpaloaltonetworkspan-os11.2.7--
OSpaloaltonetworkspan-os11.2.7--
OSpaloaltonetworkspan-os11.2.7--
OSpaloaltonetworkspan-os11.2.8--
OSpaloaltonetworkspan-os11.2.9--
OSpaloaltonetworkspan-os12.1.2--
OSpaloaltonetworkspan-os12.1.3--
OSpaloaltonetworkspan-os12.1.4--
OSpaloaltonetworkspan-os12.1.4--
OSpaloaltonetworkspan-os12.1.4--
OSpaloaltonetworkspan-os12.1.4--
OSpaloaltonetworkspan-os12.1.5--
OSpaloaltonetworkspan-os12.1.6--
Apppaloaltonetworksprisma_access---
HWsiemensruggedcom_ape1808---
OSsiemensruggedcom_ape1808_firmware---

Explore more