PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation
2026-05-30T13:24:11Z•52931ecb04b8e93969177ed82d7ac8787f444843869cbda9962d846c907c5d72
active-exploitationai-abuseauthentication-bypasscontainer-securitycredential-theftendpoint-managementllmmalicious-packagesnation-statepatches-releasedphishingremote-code-executionsupply-chainvpnvulnerability-disclosure
What happened
The collection details a wave of high-impact security events and active exploitations reported by The Hacker News: an authentication-bypass in Palo Alto PAN-OS GlobalProtect (CVE-2026-0257) is being actively exploited to set up unauthorized VPN sessions; Marimo notebooks were exploited via CVE-2026-39987 leading to credential exfiltration and LLM-agent-driven post-compromise activity; a critical unauthenticated RCE in Gogs (CVSS 9.4) and ongoing exploitation of a FortiClient EMS flaw have been used to deploy credential stealers; Gitea exposes private container images (CVE-2026-27771); and a微软/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 52931ecb04b8e93969177ed82d7ac8787f444843869cbda9962d846c907c5d72
- Enrichment time
- 2026-05-30T13:24:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.