Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Exploitation of PAN-OS Vulnerability CVE-2026-0257

Critical Exploitation of PAN-OS Vulnerability CVE-2026-0257

Posted on May 30, 2026 By CWS

Palo Alto Networks has recently been embroiled in security challenges due to a vulnerability, CVE-2026-0257, affecting its PAN-OS and Prisma Access systems. This authentication bypass flaw has garnered attention after being actively exploited, prompting its inclusion in the Known Exploited Vulnerabilities (KEV) catalog by CISA on May 29, 2026.

Vulnerability Details and Exploitation

On May 13, 2026, Palo Alto Networks issued a security advisory regarding the vulnerability. The flaw allows remote attackers to forge authentication override cookies, enabling unauthorized VPN connections via the GlobalProtect gateway. This issue stems from a non-default feature known as “authentication override.”

The vulnerability is exploited when the certificate used for these override cookies is shared with other features, like the HTTPS service. The decryption process, lacking signature verification, allows attackers to bypass authentication by forging valid cookies.

Documented Attack Waves

Rapid7 reported the first instance of exploitation on May 17, 2026, with attacks traced back to IP addresses hosted on Vultr. Subsequent suspicious activities were noted on May 18, highlighting unauthorized cookie-based authentication attempts targeting local admin accounts.

A second wave on May 21, originating from Dromatics Systems, saw attackers using the machine name DESKTOP-GP01. This round involved full VPN IP assignments to attackers, granting them direct access to internal networks. Across both waves, the consistency in spoofed MAC addresses suggests a single threat actor was responsible.

Mitigation Measures and Urgent Actions

Organizations are urged to promptly update to patched versions of PAN-OS and Prisma Access. Critical updates include PAN-OS 12.1.4-h6 / 12.1.7, among others, and Prisma Access 11.2.7-h13 or later. Disabling the authentication override feature and using dedicated certificates for cookie encryption are recommended steps.

Security teams should actively hunt for Indicators of Compromise (IOCs) and deploy detection rules to safeguard against potential threats. Despite a medium CVSSv4 score, Rapid7 emphasizes the critical nature of CVE-2026-0257, given its potential as an entry point for attackers.

As the exploitation of this vulnerability continues, immediate action is vital to secure systems and prevent unauthorized network access. Organizations must prioritize these updates to protect their infrastructure from ongoing cyber threats.

Cyber Security News Tags:authentication bypass, CISA, CVE-2026-0257, cyber threat, Cybersecurity, GlobalProtect, internet security, network security, PAN-OS, Prisma Access, Rapid7, VPN security, Vulnerability, vulnerability patching

Post navigation

Previous Post: Google Chrome Enhances Security with Device-Bound Credentials

Related Posts

Google Announces Android Theft Protection Feature to Make Your Device Harder Target for Hackers Google Announces Android Theft Protection Feature to Make Your Device Harder Target for Hackers Cyber Security News
Belarusian Spyware ResidentBat Targets Journalists with Precision Belarusian Spyware ResidentBat Targets Journalists with Precision Cyber Security News
Linux CUPS Vulnerability Let Attackers Remote DoS and Bypass Authentication Linux CUPS Vulnerability Let Attackers Remote DoS and Bypass Authentication Cyber Security News
What Is Out-of-Bounds Read and Write Vulnerability? What Is Out-of-Bounds Read and Write Vulnerability? Cyber Security News
Vulnerabilities Exposed in Socomec DIRIS M-70 Device Vulnerabilities Exposed in Socomec DIRIS M-70 Device Cyber Security News
Microsoft Teams Introduces Automatic Alerts for Malicious Links from Attackers Microsoft Teams Introduces Automatic Alerts for Malicious Links from Attackers Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Exploitation of PAN-OS Vulnerability CVE-2026-0257
  • Google Chrome Enhances Security with Device-Bound Credentials
  • GREYVIBE Hackers Exploit AI for Sophisticated Cyberattacks
  • Fake Video Players Spread Malware: Crypto Miner and RAT
  • ChatGPT Exploit Turns Web Pages Into Phishing Tools

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Exploitation of PAN-OS Vulnerability CVE-2026-0257
  • Google Chrome Enhances Security with Device-Bound Credentials
  • GREYVIBE Hackers Exploit AI for Sophisticated Cyberattacks
  • Fake Video Players Spread Malware: Crypto Miner and RAT
  • ChatGPT Exploit Turns Web Pages Into Phishing Tools

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark