Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
  • Home
  • Attack Feeds
  • Attackers are exploiting Palo Alto Networks defect that initially flew under the radar  – CyberScoop
AttackFeed by Joe Wagner | Attackers are exploiting Palo Alto Networks defect that initially flew under the radar  - CyberScoop

Attackers are exploiting Palo Alto Networks defect that initially flew under the radar  – CyberScoop

Posted on June 1, 2026 By Matt Kapko No Comments on Attackers are exploiting Palo Alto Networks defect that initially flew under the radar  – CyberScoop
Attack Feeds

Researchers and threat hunters are scrambling to respond to an actively exploited authentication-bypass vulnerability affecting Palo Alto Networks customers’ firewalls. 

The company initially tagged CVE-2026-0257 with a medium-severity rating when it disclosed the defect May 13, but quickly reassessed it as critical after Rapid7 observed and confirmed active exploitation in the wild. The Cybersecurity and Infrastructure Security Agency followed suit, and added the vulnerability to its known exploited vulnerabilities catalog Friday.

The escalated threat posed by the defect, which allows remote attackers to bypass security restrictions and establish a VPN connection to an affected firewall, showcases how quickly a seemingly mild vulnerability can turn into an urgent warning. 

“Palo Alto Networks is actively monitoring limited exploitation attempts targeting CVE-2026-0257 on unpatched PAN-OS devices where mitigations have not been applied,” a company spokesperson said in a statement. The company on Friday urged all customers to immediately apply the patch or follow its recommended steps for mitigation. 

The vendor and Rapid7, which first observed exploitation May 17 in a customer environment, declined to say how many organizations are impacted thus far. Yet, Douglas McKee, director of vulnerability intelligence at Rapid7, warned: “We’ve continued to see new victims roll in, including a couple of customers hit within just an hour of each other during a second wave of activity” on May 21. 

Jake Knott, security researcher at watchTowr, told CyberScoop the vulnerability and resulting exploits follows a recurring trend wherein attackers target exposed network edge devices and rapidly identify, develop and weaponize exploits for initial access. 

“This is yet another authentication bypass on a device whose sole job is to guard the front door to an organization’s network,” he said. “What stands out is how simple it is — an attacker can forge a valid authentication cookie using nothing more than the appliance’s publicly available TLS certificate. The entire exploit is a single HTTP request.”

The vulnerability has a few requisites that limit exposure, specifically posing risk to some Palo Alto Networks customers running GlobalProtect portal or gateway configured to enable authentication override cookies. 

“The cookie encryption and decryption certificate must be reused with another feature, which potentially exposes the public key for that certificate,” said Caitlin Condon, vice president of security research at VulnCheck.

“It’s difficult to say how many deployments meet those criteria for exploitability, but Palo Alto Networks firewalls have a very large footprint, which means even uncommon configurations can present significant attack surface area,” she added.

Rapid7 said the same attacker or group is likely responsible for both waves of exploitation last month, but in many cases attackers are not establishing a full VPN connection or moving to other parts of the impacted network. 

The attackers are “highly opportunistic and clearly monitor the security research community,” McKee said. “Attackers are purposefully weaponizing medium-severity vulnerabilities, which are typically lower priority or blind spots for organizations.”

Multiple threat clusters are swarming to the opportunity and quickly adapting to published research.  Researchers have not attributed the malicious activity to any specific threat groups. 

“Their exact origins and long-term objectives remain unclear, as they currently seem focused purely on opportunistic initial access rather than targeted, long-term espionage,” McKee said. 

Palo Alto Networks said it discovered the vulnerability internally through its use of frontier AI tools. Yet, within days of its public disclosure, initial assessments were proven inadequate.

“This is a pattern we continue to see — the urgency only arrives after exploitation is underway,” Knott said. “Organizations that wait for confirmation of active exploitation before patching will consistently find themselves reacting too late.”

The post Attackers are exploiting Palo Alto Networks defect that initially flew under the radar appeared first on CyberScoop.

  –

Read More  – CyberScoop 

Post navigation

❮ Previous Post: What One Predator Case Can Reveal About an Online Platform’s Safety Gaps  – Hackread – Cybersecurity News, Data Breaches, AI and More
Next Post: Why Encrypted File Sharing Is Essential for Modern Businesses  – Hackread – Cybersecurity News, Data Breaches, AI and More ❯

You may also like

AttackFeed by Joe Wagner | Attackers are exploiting Palo Alto Networks defect that initially flew under the radar  - CyberScoop
Attack Feeds
Ex-L3Harris executive sentenced to 87 months in prison for selling zero-day exploits to Russian broker  – CyberScoop
February 24, 2026
AttackFeed by Joe Wagner | Harvester Deploys Linux GoGra Backdoor in South Asia Using Microsoft Graph API  - The Hacker News
Attack Feeds
Harvester Deploys Linux GoGra Backdoor in South Asia Using Microsoft Graph API  – The Hacker News
April 22, 2026
AttackFeed by Joe Wagner | Chrome Extension Turns Malicious After Ownership Transfer, Enabling Code Injection and Data Theft  - The Hacker News
Attack Feeds
Chrome Extension Turns Malicious After Ownership Transfer, Enabling Code Injection and Data Theft  – The Hacker News
March 9, 2026
AttackFeed by Joe Wagner | Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker  - Krebs on Security
Attack Feeds
Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker  – Krebs on Security
March 11, 2026

Leave a Reply Cancel reply

You must be logged in to post a comment.

  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.