HIGH: Palo Alto GlobalProtect Authentication Bypass Under Active Exploitation (CVE-2026-0257)
Palo Alto Networks confirmed active exploitation of CVE-2026-0257, an authentication bypass in PAN-OS GlobalProtect that lets attackers establish unauthorized VPN sessions without credentials. CVSS 7.8, added to CISA KEV, patches available across all supported branches.