A critical authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect (CVE-2026-0257) has been added to CISA’s Known Exploited Vulnerabilities catalog after Rapid7 researchers observed active exploitation across numerous customer environments dating back to at least May 17, 2026.

The flaw, which affects the GlobalProtect portal and gateway, was initially rated as medium severity but has been reassessed as critical following the discovery of widespread exploitation. Remote attackers can bypass authentication entirely, gaining VPN access without valid credentials. This effectively gives attackers a foothold inside the corporate network through the very product designed to secure remote access. Palo Alto Networks has released patches, and organizations are urged to update immediately.

Source

Reporting from Dark Reading, CyberScoop, and CISA KEV Catalog.

Commentary

There’s a particular irony when the VPN gateway — the literal front door of your corporate network — becomes the easiest way in. Authentication bypass on a GlobalProtect instance means attackers don’t even need stolen credentials; they just walk through the door your security team set up to keep them out.

The severity reclassification from medium to critical tells the real story here. Initial scoring underestimated the exploitability, and by the time it was reassessed, attackers were already inside multiple organizations. This is a good reminder that CVSS scores are starting points, not gospel. If you run GlobalProtect, check your patch status and review VPN access logs for anomalies going back to mid-May.

By Allan