Palo Alto Networks PAN-OS Authentication Vulnerability Bypass Exploited in the Wild
AI-summarised brief · reviewed before publication
A Palo Alto Networks authentication bypass vulnerability, CVE-2026-0257, is being actively exploited in the wild. The vulnerability, affecting PAN-OS and Prisma Access, allows remote attackers to forge authentication override cookies and establish unauthorized VPN connections. The flaw exists in a non-default feature and can be triggered when a shared certificate is used for encryption and decryption. Rapid7 identified the earliest exploitation on May 17, 2026, with a first wave of attacks originating from IPs hosted on Vultr.