PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

2026-05-30T19:24:13Zab2ce8431b9e5f0463aadeafc5a4e284ccce7bbc7cf0a86db153a4d6388c2c48
active-exploitationai-llm-threatschatgphishcredential-theftforticlient-emsgiteaglasswormglobalprotectgogsgreyvibekimsukymalicious-packagesmalwaremarimomuddywaternpmnugetpan-ospatchingphishingprisma-accesssharepointsupply-chainthreat-actorsvulnerability

What happened

Multiple active and high-risk campaigns and vulnerabilities reported: active exploitation of PAN-OS/GlobalProtect authentication bypass (CVE-2026-0257), ongoing abuse of a Marimo notebook vulnerability (CVE-2026-39987) leading to cloud-credential theft, exposed private container images via Gitea (CVE-2026-27771), and a SharePoint RCE (CVE-2026-45659). Additionally, critical supply-chain and package-based attacks (malicious npm/NuGet packages, GlassWorm developer supply-chain activity), credential-stealing campaigns leveraging FortiClient EMS exploitation, and novel AI/LLM attack surfaces (Chat

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
ab2ce8431b9e5f0463aadeafc5a4e284ccce7bbc7cf0a86db153a4d6388c2c48
Enrichment time
2026-05-30T19:24:13Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.