Palo Alto Confirms In-the-Wild Abuse of GlobalProtect Auth Bypass (CVE-2026-0257)
An unknown actor is exploiting a 7.8-rated authentication bypass in PAN-OS portals and gateways to slip past GlobalProtect logins.

Palo Alto Networks says it has observed active exploitation of a recently patched PAN-OS flaw that lets attackers bypass authentication on GlobalProtect portals.
The bug is tracked as CVE-2026-0257, carrying a CVSS score of 7.8. It affects the portal and gateway components of PAN-OS, and a successful exploit hands an unauthenticated attacker access to the GlobalProtect interface — the same door legitimate remote workers walk through every day.
The vendor has not publicly named the threat actor. It has not attributed the activity to a known cluster, nor published indicators of compromise tied to a specific campaign at the time of writing. What Palo Alto has said is straightforward: exploitation is happening, and customers should patch.
GlobalProtect appliances are a perennial target. They sit at the network edge. They terminate VPN sessions for employees, contractors, and admins. Auth bypasses against them have historically been chained with post-exploitation tooling to drop webshells, harvest credentials, or pivot into internal networks. Whether this actor is doing the same is not yet documented.
No public proof-of-concept has surfaced so far. That window tends to be short. Once a PAN-OS edge bug is confirmed exploited, broader scanning and opportunistic abuse usually follow within days.
Administrators should consult Palo Alto's advisory on the security advisories portal for the exact fixed PAN-OS train and any workarounds. Cloud-delivered Prisma Access tenants are typically patched by the vendor; self-managed firewalls are not.
What defenders should do now
- Apply the fixed PAN-OS release for your branch as soon as your change window allows. If you cannot patch immediately, restrict portal exposure to known IP ranges where feasible.
- Pull GlobalProtect portal and gateway logs back at least 30 days and hunt for unauthenticated session establishment, unexpected MFA bypasses, and logins from residential or hosting-provider ASNs.
- Rotate any credentials, API keys, or certificates accessible from a compromised firewall. Assume material on the device is exposed if you find evidence of access.
- Review configuration backups and admin accounts for unauthorized additions.
Jurisdictionally, U.S. operators of affected appliances who suffer confirmed data exposure may face SEC Item 1.05 disclosure obligations and state-level breach notification under statutes such as California's CCPA. UK operators answer to the ICO under UK GDPR; Australian entities to the OAIC under the Notifiable Data Breaches scheme. The clock on those notifications starts when you know, not when you finish investigating.
Expect more detail — and likely IoCs — as the vendor's incident response telemetry catches up with the activity.



