Palo Alto Networks warns that a newly disclosed medium-severity vulnerability affecting PAN-OS and Prisma Access is being actively exploited. The flaw, tracked as CVE-2026-0257, is described as an authentication bypass issue that could allow attackers to establish GlobalProtect VPN connections without proper authorization. Security researchers and reports indicate that attackers are using the bypass as an initial step in attempts to breach corporate networks.
The vulnerability has a reported CVSS score of 7.8, and it impacts components used for VPN access. Palo Alto’s advisory notes the risk of unauthorized access and highlights that exploitation is occurring in the wild. While the available coverage emphasizes the authentication bypass mechanism and its use to set up VPN connections, details on attacker methods beyond the bypass are limited in the excerpts.
Organizations using PAN-OS and Prisma Access are urged to follow Palo Alto’s guidance, including applying available mitigations or patches and reviewing exposure to GlobalProtect services.