Lyrie
Active Exploitation
1 sources verified·1 min read
By Lyrie Threat Intelligence·5/31/2026

0day Intel: Palo Alto GlobalProtect (CVE-2026-0257, CVSS 9.8) is actively exploited. Auth ov

Source: X search for actively exploited 2026

Posted: 2026-05-30T10:14:38.000Z

Likes: 11

Full Tweet

Palo Alto GlobalProtect (CVE-2026-0257, CVSS 9.8) is actively exploited. Auth override cookies use a cert; when shared with the HTTPS portal, attackers extract the public key and forge valid cookies. Fixed: PAN-OS 11.2.12, 12.1.7. CISA patches due June 19.

Source Link

https://x.com/i/status/2060666183779586078

Lyrie Verdict

Lyrie's autonomous defense layer flags this class of exposure the moment it surfaces — no signature update required.

Validated sources

  1. [1]@1623161822 on X