Palo Alto PAN-OS VPN Flaw Exploited
Analysis based on 9 articles · First reported May 30, 2026 · Last updated Jun 15, 2026
The active exploitation of CVE-2026-0257 in Palo Alto Networks' PAN-OS software creates significant cybersecurity risks for organizations globally, potentially leading to unauthorized network access and data breaches. This event negatively impacts Palo Alto Networks' stock price and reputation, while boosting the visibility and demand for cybersecurity services from companies like Metasploit.
Palo Alto Networks has issued urgent warnings regarding the active exploitation of CVE-2026-0257, a critical authentication bypass vulnerability affecting its PAN-OS GlobalProtect portals and gateways. This flaw allows unauthenticated remote attackers to establish unauthorized VPN connections. Palo Alto Networks addressed the vulnerability on May 13, 2026, but active exploitation was confirmed by cybersecurity firm Metasploit starting May 17, 2026. The U.S. United States — Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) catalog on May 29, 2026. Attacks have originated from hosting providers like Vultr and Dromatics Systems, with a consistent spoofed MAC address suggesting a single threat actor. While many probes occurred, only a portion resulted in full VPN session establishment. Organizations are urged to immediately upgrade to patched versions, disable the authentication override feature if not needed, or generate a dedicated certificate for cookie encryption, and hunt for indicators of compromise.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard