Palo Alto Networks Unit 42 is tracking active exploitation of CVE-2026-0257, an authentication bypass vulnerability in PAN-OS GlobalProtect portal and gateway components. An unidentified threat actor is using this flaw to circumvent security controls and initiate unauthorized VPN connections. The CVE was added to CISA's Known Exploited Vulnerabilities catalog on May 29. No post-access lateral movement has been confirmed yet. The report provides specific indicators of compromise including attacker IP addresses and suspicious host identifiers/MAC addresses to search for in GlobalProtect logs, along with post-PoC hardcoded client configuration values to monitor. Organizations are advised to hunt for these indicators, apply available mitigations or patches, and activate incident response protocols for any confirmed gateway-connected events.

3m read timeFrom unit42.paloaltonetworks.com
Post cover image
Table of contents
Palo Alto Networks Product Protections for PAN-OS CVE-2026-0257Indicators of the ActivityAdditional Resources
3 Impressions