Lyrie
Actively Exploited
ACTIVELY EXPLOITED4 sources verified·1 min read
By Lyrie Threat Intelligence·5/29/2026

LOW: CVE-2026-0257 actively exploited — multiple vendors

CVE: CVE-2026-0257

CVSS: 0 (v3) — ``

Severity: LOW

Status: ✅ Confirmed exploited in the wild (CISA KEV)

Affected

_See vendor advisory_

Summary

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.

Panorama and Cloud NGFW are not impacted by these issues.

Verified Sources

References

  • https://security.paloaltonetworks.com/CVE-2026-0257

_Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation._

Lyrie Verdict

Lyrie's autonomous detection layer catches active exploitation primitives at machine speed — closing the gap between disclosure and weaponization that traditional defense simply can't cover.

Validated sources

  1. [1]NVD
  2. [2]GitHub Advisory
  3. [3]MITRE
  4. [4]CISA KEV