Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks

2026-05-30T19:23:57Z826fa2ae2785a87054b2af43c26611d209477a0e5608dd5fbcc9cd72de7c801e
CIFSwitchCVE-2026-0257CVE-2026-35616EKZactive exploitationauthentication bypassbotnet takedownchatgpt abusedata breachddos-as-a-serviceforticlientfortinetglobalprotectinfostealerlinux kernellocal privilege escalationmalware distributionpalo altorootvpn

What happened

Multiple high-impact security stories: attackers are actively exploiting a PAN-OS GlobalProtect authentication bypass (CVE-2026-0257) to attempt network breaches. A local Linux kernel privilege-escalation vulnerability dubbed “CIFSwitch” can allow forging CIFS auth key descriptions and gaining root on multiple distributions. Threat actors are also abusing ChatGPT share links to host fake outage pages delivering malware, and exploiting a FortiClient EMS authentication bypass (CVE-2026-35616) to deploy an undocumented credential stealer named EKZ. Additional reporting covers DDoS-as-a-Service, a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
826fa2ae2785a87054b2af43c26611d209477a0e5608dd5fbcc9cd72de7c801e
Enrichment time
2026-05-30T19:23:57Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.