Palo Alto Networks PAN-OS GlobalProtect Auth Bypass

Attackers are actively exploiting a PAN-OS GlobalProtect authentication bypass vulnerability to gain unauthorized VPN access to exposed Palo Alto Networks firewalls. An attacker who successfully exploits CVE-2026-0257 can:

– Establish unauthorized VPN sessions through affected GlobalProtect gateways.
– Bypass authentication controls without valid user credentials.
– Gain network-level access typically reserved for authenticated VPN users.
– Potentially facilitate further reconnaissance, lateral movement, or follow-on attacks within the victim environment.