Palo Alto Networks Vulnerability Exploited After Disclosure
TL;DR. Attackers exploited a critical authentication bypass in Palo Alto Networks PAN-OS just days after its public disclosure. - CVE-2026-0257 allowed threat actors to establish VPN connections to vulnerable firewalls. - Rapid7 observed initial exploitation attempts four days post-disclosure from multiple hosting providers. - The US cybersecurity agency CISA added the flaw to its Known Exploited Vulnerabilities catalog.
- Threat actors exploited CVE-2026-0257, an authentication bypass in Palo Alto Networks PAN-OS.
- Exploitation began four days after public disclosure, allowing VPN access to internal networks.
- Palo Alto Networks and CISA confirmed active exploitation, urging federal agencies to patch.
Sources
- bleepingcomputer.com — bleepingcomputer.com
- Recent Palo Alto Networks Vulnerability Exploited for Weeks — securityweek.com