PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation
2026-05-30T19:24:13Z•ab2ce8431b9e5f0463aadeafc5a4e284ccce7bbc7cf0a86db153a4d6388c2c48
active-exploitationai-llm-threatschatgphishcredential-theftforticlient-emsgiteaglasswormglobalprotectgogsgreyvibekimsukymalicious-packagesmalwaremarimomuddywaternpmnugetpan-ospatchingphishingprisma-accesssharepointsupply-chainthreat-actorsvulnerability
What happened
Multiple active and high-risk campaigns and vulnerabilities reported: active exploitation of PAN-OS/GlobalProtect authentication bypass (CVE-2026-0257), ongoing abuse of a Marimo notebook vulnerability (CVE-2026-39987) leading to cloud-credential theft, exposed private container images via Gitea (CVE-2026-27771), and a SharePoint RCE (CVE-2026-45659). Additionally, critical supply-chain and package-based attacks (malicious npm/NuGet packages, GlassWorm developer supply-chain activity), credential-stealing campaigns leveraging FortiClient EMS exploitation, and novel AI/LLM attack surfaces (Chat
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- ab2ce8431b9e5f0463aadeafc5a4e284ccce7bbc7cf0a86db153a4d6388c2c48
- Enrichment time
- 2026-05-30T19:24:13Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.