Palo Alto Firewall Has an Unpatched Critical RCE Today (CVE-2026-0300)

Author: VulnTracker Published: May 6, 2026 Source: https://vulntracker.io/blog/palo-alto-pan-os-cve-2026-0300-unauth-rce-active-exploitation/ Summary VulnTracker reports on CVE-2026-0300, a critical unauthenticated remote code execution flaw in Palo Alto Networks PAN-OS firewalls that, at the time of writing (May 6, 2026), was under active exploitation with no patch available until May 13, 2026. An unauthenticated attacker can obtain full root control … Read more

Critical and Already Being Exploited: PAN-OS GlobalProtect Auth Bypass (CVE-2026-0257)

Author: VulnTracker Published: June 2, 2026 Source: https://vulntracker.io/blog/palo-alto-globalprotect-auth-bypass-cve-2026-0257-actively-exploited Summary VulnTracker reports on CVE-2026-0257, a CVSS 9.1 critical authentication bypass in Palo Alto Networks PAN-OS GlobalProtect that is being actively exploited in the wild and was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on May 29, 2026. A remote, unauthenticated attacker can bypass authentication … Read more

Rapid7 Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257)

Author: Rapid7 Published: May 29, 2026 (last updated June 3, 2026) Source: https://www.rapid7.com/blog/post/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257/ Summary Rapid7 reports active in-the-wild exploitation of CVE-2026-0257, an authentication bypass in the Palo Alto Networks PAN-OS GlobalProtect portal/gateway. The flaw stems from improper certificate handling in the authentication override feature: when the certificate used to encrypt authentication-override cookies is reused for … Read more