PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

2026-05-31T01:24:14Zc8dc4652028091b84051ef5d351f02a076a16575eca86206d406f4bc209ab2b4
APT-russia-linked','SharePoint','patching-guidance','CERT-InChatGPTChatGPhishFortiClient-EMSGREYVIBEGiteaGlassWormGlobalProtectGogsLLM-agentMarimoNuGetPAN-OSRCEVPNactive-exploitationauthentication-bypasscloud-credential-theftcontainer-image-exposurecredential-stealermalicious-packagenpmphishingprompt-injectionsupply-chain

What happened

The feed highlights a wave of actively exploited and high-impact issues across VPN, cloud, supply-chain and AI surfaces. Notable items include an active exploitation of PAN‑OS/GlobalProtect authentication bypass (CVE-2026-0257), Marimo exploitation leading to cloud credential theft and LLM-driven post‑exploitation (CVE-2026-39987), a critical Gogs RCE (CVSS 9.4) under disclosure, and ongoing abuse of FortiClient EMS to deploy credential stealers. Supply‑chain attacks continue to proliferate—malicious NuGet/npm packages and the GlassWorm developer-supply-chain campaign—while a ChatGPT renderer/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
c8dc4652028091b84051ef5d351f02a076a16575eca86206d406f4bc209ab2b4
Enrichment time
2026-05-31T01:24:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation · Baitaphish