Multiple outlets report that a Palo Alto Networks PAN-OS vulnerability tied to GlobalProtect VPN is being exploited in the wild. Rapid7 and other researchers say attackers are using an authentication-bypass weakness to gain unauthorized access to GlobalProtect portals, moving the issue from an advisory stage to active exploitation. TechRadar and The Register both note that the flaw was fixed previously and is now appearing in real-world attacks, prompting renewed calls for urgent patching by PAN-OS users.
Dark Reading adds that exploitation requires certain conditions, but that adversaries have carried out attacks in at least two waves that began in mid-May. Infosecurity Magazine and The Hacker News state that Palo Alto Networks has observed “active exploitation” by an unknown threat actor.
The Hacker News identifies the vulnerability as CVE-2026-0257 with a CVSS score of 7.8 and describes it as an authentication bypass affecting the portal and gateway components of PAN-OS software. Across sources, the common recommendation is to apply Palo Alto’s available fixes and review exposure to GlobalProtect systems.