HIGH: Palo Alto Networks GlobalProtect Authentication Bypass Under Active Exploitation
CVE-2026-0257 is an authentication bypass in PAN-OS GlobalProtect portal and gateway components, exploited in the wild since May 17, 2026. Attackers forge authentication override cookies when administrators reuse a certificate between authentication override and the HTTPS service, dropping straight onto the corporate VPN as legitimate users. CISA added the bug to KEV with a June 19 federal patch deadline.