PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation
2026-05-31T07:24:10Z•202998d3535dd6cd7755bf24f30a38c77098741a152e40455d1c98b4087d4860
CERT-InFortiClientGiteaGogsLLM-abuseMarimoPAN-OSSharePointactive exploitationauthentication-bypasscredential-theftmalwarenpmnugetphishingprompt-injectionremote-code-executionsupply-chain
What happened
The feed reports widespread, high-impact security activity: multiple remotely exploitable and actively exploited vulnerabilities (notably PAN-OS GlobalProtect authentication bypass under active exploitation) alongside supply-chain malware and credential-stealing campaigns. Key disclosed flaws include PAN-OS/Prisma Access authentication bypass (CVE-2026-0257, CVSS 7.8), Gitea private image exposure (CVE-2026-27771, CVSS 8.2), Microsoft SharePoint RCE (CVE-2026-45659, CVSS 8.8), and a Marimo notebook compromise (CVE-2026-39987) leading to cloud credential theft and LLM-agent post-exploitation. O
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 202998d3535dd6cd7755bf24f30a38c77098741a152e40455d1c98b4087d4860
- Enrichment time
- 2026-05-31T07:24:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.