Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks
2026-05-30T19:23:57Z•826fa2ae2785a87054b2af43c26611d209477a0e5608dd5fbcc9cd72de7c801e
CIFSwitchCVE-2026-0257CVE-2026-35616EKZactive exploitationauthentication bypassbotnet takedownchatgpt abusedata breachddos-as-a-serviceforticlientfortinetglobalprotectinfostealerlinux kernellocal privilege escalationmalware distributionpalo altorootvpn
What happened
Multiple high-impact security stories: attackers are actively exploiting a PAN-OS GlobalProtect authentication bypass (CVE-2026-0257) to attempt network breaches. A local Linux kernel privilege-escalation vulnerability dubbed “CIFSwitch” can allow forging CIFS auth key descriptions and gaining root on multiple distributions. Threat actors are also abusing ChatGPT share links to host fake outage pages delivering malware, and exploiting a FortiClient EMS authentication bypass (CVE-2026-35616) to deploy an undocumented credential stealer named EKZ. Additional reporting covers DDoS-as-a-Service, a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 826fa2ae2785a87054b2af43c26611d209477a0e5608dd5fbcc9cd72de7c801e
- Enrichment time
- 2026-05-30T19:23:57Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.