{"id":885,"date":"2026-06-03T11:20:29","date_gmt":"2026-06-03T05:50:29","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=885"},"modified":"2026-08-19T11:21:18","modified_gmt":"2026-08-19T05:51:18","slug":"palo-alto-globalprotect-vulenarbility-exploited-in-attacks","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\/","title":{"rendered":"Palo Alto GlobalProtect Vulnerability CVE-2026-0257 Exploited in Active Attacks"},"content":{"rendered":"<p>Palo Alto Networks has warned that attackers are actively exploiting CVE-2026-0257, a Palo Alto GlobalProtect vulnerability that can allow unauthorized VPN access to affected PAN-OS deployments. The flaw impacts specific GlobalProtect portal and gateway configurations that use authentication override cookies, creating a pathway for attackers to bypass authentication controls under certain conditions.<\/p>\n<p>The company has confirmed limited exploitation attempts against unpatched systems without mitigations applied. Security researchers have also reported successful exploitation in customer environments, including unauthorized VPN access in some cases. The vulnerability was later added to CISA\u2019s <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-are-known-exploited-vulnerabilities-kev\/\">Known Exploited Vulnerabilities<\/a> (KEV) catalog, reinforcing the need for organizations to review exposure, apply PAN-OS updates, and implement vendor-recommended mitigations.<\/p>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/xdr\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tStrengthen endpoint security with Hexnode XDR<\/a>\r\n    \t\t<\/center><\/p>\n<h2>Technical Deep Dive &#8211; Understanding the GlobalProtect Authentication Bypass<\/h2>\n<p>CVE-2026-0257 is an authentication bypass vulnerability affecting the GlobalProtect portal and gateway in Palo Alto Networks PAN-OS. The issue applies to deployments where authentication override cookies are enabled and a specific certificate configuration exists.<\/p>\n<p>Authentication override allows GlobalProtect to issue a cookie after a successful login. The user can then use that cookie for future access instead of repeatedly re-authenticating.<\/p>\n<p>In vulnerable deployments, attackers may be able to:<\/p>\n<ul>\n<li>Forge authentication override cookies.<\/li>\n<li>Present those cookies to GlobalProtect services as valid authentication artifacts.<\/li>\n<li>Bypass normal authentication controls.<\/li>\n<li>Establish unauthorized VPN access without legitimate user credentials.<\/li>\n<\/ul>\n<p>According to Palo Alto Networks, exposure requires both authentication override cookies and the affected certificate configuration. Palo Alto recommends using a dedicated certificate for authentication override cookies and not reusing the GlobalProtect portal or gateway certificate for this purpose.<\/p>\n<p>Rapid7 reported exploitation activity involving forged authentication override cookies that targeted the local administrator account. In some affected environments, attackers were able to establish VPN sessions and receive VPN access. Rapid7 also reported that it did not observe confirmed successful lateral movement in the customer environments it investigated.<\/p>\n<p>The operational risk is significant because GlobalProtect gateways often act as trusted entry points into enterprise networks. Successful exploitation could allow attackers to access internal resources available through the VPN connection and may support follow-on activity such as reconnaissance or attempts to expand access.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-challenges.jpeg?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Top 10 Cybersecurity Challenges for Enterprises<\/h4><p>Understanding enterprise cybersecurity risks, mitigation strategies, and resilience.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/top-10-cybersecurity-challenges-for-enterprises\/\" aria-label=\"Top 10 Cybersecurity Challenges for Enterprises\"><\/a><\/div><\/div><\/div>\n<h2>The Hexnode Solution<\/h2>\n<p>While patching remains the primary remediation step, organizations also need visibility into potential post-authentication activity that may occur after unauthorized VPN access is established.<\/p>\n<ul>\n<li><a href=\"https:\/\/www.hexnode.com\/blogs\/xdr-extended-detection-and-response\/\">Hexnode XDR<\/a> can help security teams correlate endpoint telemetry and XDR security alerts with UEM context, such as device compliance status, user identity, and location, to support threat hunting and active containment. This visibility can support threat hunting efforts by helping security teams correlate endpoint telemetry, network logs, and UEM context during investigations.<\/li>\n<\/ul>\n<ul>\n<li><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> can help enforce device compliance requirements, strengthen device posture management, and support identity-aware access controls. By ensuring that only trusted and compliant devices can access corporate resources, organizations can add additional layers of validation beyond perimeter-based access controls.<\/li>\n<\/ul>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-.jpg?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity kit\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-.jpg?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--300x225.jpg?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--768x576.jpg?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--133x100.jpg?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity kit\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Cybersecurity kit\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Enterprise cybersecurity kit featuring frameworks, incident policies, checklists, and security best practices.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/resource-kits\/cybersecurity-kit\/'>\n                            DOWNLOAD\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>Conclusion<\/h2>\n<p>The active exploitation of CVE-2026-0257 demonstrates the continued risk posed by externally exposed access infrastructure and highlights the importance of secure certificate management practices. Organizations using affected GlobalProtect deployments should prioritize remediation and review logs for signs of unauthorized VPN activity.<\/p>\n<p>Addressing the Palo Alto GlobalProtect vulnerability requires more than patching alone. Strong monitoring, endpoint visibility, layered access controls, and continuous validation of trusted devices can help reduce exposure and improve detection of post-authentication threats.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Strengthen visibility beyond perimeter access<\/h5><p>Start a free trial to improve detection and response readiness.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> SIGN UP NOW<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Palo Alto Networks has warned that attackers are actively exploiting CVE-2026-0257, a Palo Alto GlobalProtect&#8230;<\/p>\n","protected":false},"author":5,"featured_media":886,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[20,21],"class_list":["post-885","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-network-and-vpn","category-patch-management","product_category-identity-provider","tab_group-vulnerabilities"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Palo Alto GlobalProtect Vulnerability Exploited in Attacks<\/title>\n<meta name=\"description\" content=\"Palo Alto warns CVE-2026-0257 is being exploited to bypass GlobalProtect authentication and gain unauthorized VPN access.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Palo Alto GlobalProtect Vulnerability Exploited in Attacks\" \/>\n<meta property=\"og:description\" content=\"Palo Alto warns CVE-2026-0257 is being exploited to bypass GlobalProtect authentication and gain unauthorized VPN access.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-03T05:50:29+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-19T05:51:18+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/palo-alto-globalprotect-vulnerability.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sophia Hart\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sophia Hart\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\\\/\"},\"author\":{\"name\":\"Sophia Hart\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\"},\"headline\":\"Palo Alto GlobalProtect Vulnerability CVE-2026-0257 Exploited in Active Attacks\",\"datePublished\":\"2026-06-03T05:50:29+00:00\",\"dateModified\":\"2026-08-19T05:51:18+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\\\/\"},\"wordCount\":585,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/palo-alto-globalprotect-vulnerability.jpeg?format=webp\",\"articleSection\":[\"Network and VPN\",\"Patch Management\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\\\/\",\"name\":\"Palo Alto GlobalProtect Vulnerability Exploited in Attacks\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/palo-alto-globalprotect-vulnerability.jpeg?format=webp\",\"datePublished\":\"2026-06-03T05:50:29+00:00\",\"dateModified\":\"2026-08-19T05:51:18+00:00\",\"description\":\"Palo Alto warns CVE-2026-0257 is being exploited to bypass GlobalProtect authentication and gain unauthorized VPN access.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/palo-alto-globalprotect-vulnerability.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/palo-alto-globalprotect-vulnerability.jpeg?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"palo alto globalprotect vulnerability\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Palo Alto GlobalProtect Vulnerability CVE-2026-0257 Exploited in Active Attacks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\",\"name\":\"Sophia Hart\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"caption\":\"Sophia Hart\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/sophia-hart\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Palo Alto GlobalProtect Vulnerability Exploited in Attacks","description":"Palo Alto warns CVE-2026-0257 is being exploited to bypass GlobalProtect authentication and gain unauthorized VPN access.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\/","og_locale":"en_US","og_type":"article","og_title":"Palo Alto GlobalProtect Vulnerability Exploited in Attacks","og_description":"Palo Alto warns CVE-2026-0257 is being exploited to bypass GlobalProtect authentication and gain unauthorized VPN access.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-06-03T05:50:29+00:00","article_modified_time":"2026-08-19T05:51:18+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/palo-alto-globalprotect-vulnerability.jpeg?format=webp","type":"image\/jpeg"}],"author":"Sophia Hart","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Sophia Hart","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\/"},"author":{"name":"Sophia Hart","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430"},"headline":"Palo Alto GlobalProtect Vulnerability CVE-2026-0257 Exploited in Active Attacks","datePublished":"2026-06-03T05:50:29+00:00","dateModified":"2026-08-19T05:51:18+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\/"},"wordCount":585,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/palo-alto-globalprotect-vulnerability.jpeg?format=webp","articleSection":["Network and VPN","Patch Management"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\/","url":"https:\/\/www.hexnode.com\/threat-watch\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\/","name":"Palo Alto GlobalProtect Vulnerability Exploited in Attacks","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/palo-alto-globalprotect-vulnerability.jpeg?format=webp","datePublished":"2026-06-03T05:50:29+00:00","dateModified":"2026-08-19T05:51:18+00:00","description":"Palo Alto warns CVE-2026-0257 is being exploited to bypass GlobalProtect authentication and gain unauthorized VPN access.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/palo-alto-globalprotect-vulnerability.jpeg?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/palo-alto-globalprotect-vulnerability.jpeg?format=webp","width":1340,"height":700,"caption":"palo alto globalprotect vulnerability"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/palo-alto-globalprotect-vulenarbility-exploited-in-attacks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Palo Alto GlobalProtect Vulnerability CVE-2026-0257 Exploited in Active Attacks"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430","name":"Sophia Hart","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","caption":"Sophia Hart"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/sophia-hart\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/885","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=885"}],"version-history":[{"count":2,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/885\/revisions"}],"predecessor-version":[{"id":888,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/885\/revisions\/888"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/886"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=885"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=885"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}