Rapid7 Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257)
2026-05-29T19:23:43Z•682ba8fadb96f3fcda8ab578ec88f92426abe611505f87d12ec22d02052096bc
CVE-2026-0257GlobalProtectPAN-OSPalo Alto NetworksPrisma AccessRapid7 MDRVPN gatewayauthentication bypassobserved exploitationremote unauthenticated exploiturgent patching
What happened
Rapid7 reports observed exploitation of PAN-OS GlobalProtect authentication bypass (CVE-2026-0257). Palo Alto Networks published an advisory on 2026-05-13: when a specific configuration is present, the vulnerability allows a remote, unauthenticated attacker to establish a VPN session through the GlobalProtect gateway (affecting PAN-OS and Prisma Access). Rapid7 MDR observed successful exploitation across multiple customers (earliest observed 2026-05-17) but did not see evidence of lateral movement from compromised devices. Although the CVSSv4 score is listed as medium, Rapid7 urges treating it
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 682ba8fadb96f3fcda8ab578ec88f92426abe611505f87d12ec22d02052096bc
- Enrichment time
- 2026-05-29T19:23:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.