Palo Alto Confirms In-the-Wild Abuse of GlobalProtect Auth Bypass (CVE-2026-0257)
An unknown actor is exploiting a 7.8-rated authentication bypass in PAN-OS portals and gateways to slip past GlobalProtect logins.

Key points
- Palo Alto Networks confirms active exploitation of CVE-2026-0257, a CVSS 7.8 authentication bypass in PAN-OS.
- The flaw affects GlobalProtect portal and gateway components, giving unauthenticated attackers access to VPN entry points.
- No threat actor has been named and no indicators of compromise have been published.
- Administrators of self-managed firewalls must patch manually; cloud Prisma Access tenants are patched by the vendor.
- U.S., UK and Australian operators who confirm data exposure face statutory notification deadlines that run from the moment of discovery.
Palo Alto Networks says it has observed active exploitation of a recently patched PAN-OS flaw that lets attackers bypass authentication on GlobalProtect portals.
The bug is tracked as CVE-2026-0257, carrying a CVSS score of 7.8. It affects the portal and gateway components of PAN-OS. A successful exploit hands an unauthenticated attacker access to the GlobalProtect interface, the same entry point legitimate remote workers use every day.
We first reported on this flaw on 30 May 2026, and our 2 June story tracked how it moved from medium severity to CISA's Known Exploited Vulnerabilities catalog in sixteen days, with federal agencies given 72 hours to patch. Confirmation of continued active exploitation means the threat has not peaked.
Who is behind it?
The vendor hasn't named the actor or published indicators of compromise tied to a specific campaign. What Palo Alto has confirmed is narrow: exploitation is happening and customers should patch. Auth bypasses against edge VPN appliances have historically been chained with post-exploitation tooling to drop webshells or harvest credentials, but whether that's occurring here isn't yet documented.
Should you worry about a proof-of-concept?
No public proof-of-concept has surfaced so far. That window tends to be short. Once a PAN-OS edge bug is confirmed exploited, broader opportunistic scanning usually follows within days, so the absence of a public exploit isn't a reason to delay patching.
What should administrators do?
Consult Palo Alto's advisory on the security advisories portal for the fixed PAN-OS release and any available workarounds. If you can't patch immediately, restrict portal exposure to known IP ranges where feasible.
Pull GlobalProtect portal and gateway logs back at least 30 days. Hunt for unauthenticated session establishment, unexpected MFA bypasses, and logins from residential or hosting-provider address blocks. If you find evidence of access, rotate credentials and certificates accessible from the device and treat anything on it as potentially exposed. Review configuration backups and admin accounts for unauthorized changes.
What are the legal exposure points?
U.S. Operators who suffer confirmed data exposure may face SEC Item 1.05 disclosure obligations alongside state-level breach notification under statutes such as California's CCPA. UK operators answer to the ICO under UK GDPR; Australian entities to the OAIC under the Notifiable Data Breaches scheme. The clock on those notifications starts when you know, not when you finish investigating.
More detail and likely indicators of compromise should follow as the vendor's telemetry catches up with the activity. The speed with which this CVE reached federal patch mandates suggests regulators are watching closely; the next disclosure event from any affected organisation will be scrutinised accordingly.



