Rapid7 Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257)

2026-05-29T19:23:43Z682ba8fadb96f3fcda8ab578ec88f92426abe611505f87d12ec22d02052096bc
CVE-2026-0257GlobalProtectPAN-OSPalo Alto NetworksPrisma AccessRapid7 MDRVPN gatewayauthentication bypassobserved exploitationremote unauthenticated exploiturgent patching

What happened

Rapid7 reports observed exploitation of PAN-OS GlobalProtect authentication bypass (CVE-2026-0257). Palo Alto Networks published an advisory on 2026-05-13: when a specific configuration is present, the vulnerability allows a remote, unauthenticated attacker to establish a VPN session through the GlobalProtect gateway (affecting PAN-OS and Prisma Access). Rapid7 MDR observed successful exploitation across multiple customers (earliest observed 2026-05-17) but did not see evidence of lateral movement from compromised devices. Although the CVSSv4 score is listed as medium, Rapid7 urges treating it

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
682ba8fadb96f3fcda8ab578ec88f92426abe611505f87d12ec22d02052096bc
Enrichment time
2026-05-29T19:23:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.