PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

2026-05-31T07:24:10Z202998d3535dd6cd7755bf24f30a38c77098741a152e40455d1c98b4087d4860
CERT-InFortiClientGiteaGogsLLM-abuseMarimoPAN-OSSharePointactive exploitationauthentication-bypasscredential-theftmalwarenpmnugetphishingprompt-injectionremote-code-executionsupply-chain

What happened

The feed reports widespread, high-impact security activity: multiple remotely exploitable and actively exploited vulnerabilities (notably PAN-OS GlobalProtect authentication bypass under active exploitation) alongside supply-chain malware and credential-stealing campaigns. Key disclosed flaws include PAN-OS/Prisma Access authentication bypass (CVE-2026-0257, CVSS 7.8), Gitea private image exposure (CVE-2026-27771, CVSS 8.2), Microsoft SharePoint RCE (CVE-2026-45659, CVSS 8.8), and a Marimo notebook compromise (CVE-2026-39987) leading to cloud credential theft and LLM-agent post-exploitation. O

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
202998d3535dd6cd7755bf24f30a38c77098741a152e40455d1c98b4087d4860
Enrichment time
2026-05-31T07:24:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.