Palo Alto VPN bug graduates from advisory to active exploitation
Source summary: Palo Alto customers are being been told to patch yet another internet-facing security flaw after researchers caught attackers bypassing GlobalProtect authentication and gaining unauthorized VPN access. The flaw, tracked as CVE-2026-0257, affects PAN-OS deployments using GlobalProtect authentication override cookies under specific configurations. Palo Alto disclosed the bug on May 13 and initially assigned it a medium-severity rating, saying it was aware of attempts to exploit it but had not obs…
Why it matters: Add your own practical explanation here before publishing.
What to do: Add recommended action/checks here.
Need IT help?
Need help with hosting, Cloudflare, backups or IT support? IT Radar UK can point you in the right direction.
Get support