CVE-2026-0257: CISA Adds Actively Exploited Palo Alto PAN-OS Authentication Bypass to KEV — Two Attack Waves Confirmed, Federal Deadline June 19
CVE-2026-0257 is an actively exploited authentication bypass in Palo Alto PAN-OS GlobalProtect that lets unauthenticated attackers forge session cookies and establish unauthorized VPN connections — bypassing MFA in affected configurations. CISA added it to the KEV catalog on May 29 with a federal deadline of June 19. Rapid7 MDR confirmed successful exploitation across multiple customers in two distinct waves since May 17. CVSS raised from 7.8 to 9.1 after exploitation confirmed. Patch immediately.
