Palo Alto Networks has confirmed that hackers are actively exploiting CVE-2026-0257, an authentication bypass vulnerability in GlobalProtect VPN, to breach corporate networks.
The vulnerability allows attackers to circumvent authentication mechanisms in Palo Alto's GlobalProtect VPN gateway, potentially granting unauthorized access to internal enterprise systems without valid credentials.
What's affected
The flaw impacts Palo Alto Networks PAN-OS, the operating system powering the company's next-generation firewalls and VPN gateways. GlobalProtect is widely deployed across enterprises for secure remote access.
Active exploitation
The company confirmed the vulnerability is being weaponized in real-world attacks. Details on the attack vectors and scope of compromises remain limited, though Palo Alto has advised customers to prioritize patching efforts.
Severity
Authentication bypass flaws in VPN infrastructure are considered critical vulnerabilities because they provide direct pathways to corporate networks. Successful exploitation enables attackers to establish persistent access and move laterally to steal data or deploy ransomware.
Remediation
Palo Alto Networks has released patches for affected PAN-OS versions. The company recommends immediate updates and network monitoring for signs of exploitation, including unusual VPN connection patterns or authentication failures followed by successful logins.
Context
This incident follows a pattern of high-profile VPN vulnerabilities exploited by threat actors. Palo Alto's security products are among the most widely deployed firewalls globally, making any critical flaw a concern across numerous organizations.
The ACLU has created a toolkit for Massachusetts attorneys to expose and challenge surveillance technologies used by police to build criminal cases. The resources target facial recognition, AI-generated reports, and other concealed investigative methods.
A Verizon analysis of 22,000 incidents found 12% were carried out by internal actors, with companies now facing a new threat: AI-generated synthetic employees used to breach corporate systems. The rise of deepfake infiltration marks a significant escalation in insider attack tactics.
Attackers are actively exploiting CVE-2026-6875, a critical code execution vulnerability in ServiceNow's AI Platform. Threat intelligence firm Defused confirmed the attacks are underway.
A researcher discovered a critical WordPress remote code execution vulnerability that exploit brokers typically pay $500,000 to acquire—using only GPT5.6 and $25 in resources. The finding highlights how AI tools are democratizing vulnerability discovery.