ACTIVELY EXPLOITED4 sources verified·1 min read
By Lyrie Threat Intelligence·5/29/2026
LOW: CVE-2026-0257 actively exploited — multiple vendors
CVE: CVE-2026-0257
CVSS: 0 (v3) — ``
Severity: LOW
Status: ✅ Confirmed exploited in the wild (CISA KEV)
Affected
_See vendor advisory_
Summary
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.
Panorama and Cloud NGFW are not impacted by these issues.
Verified Sources
References
- https://security.paloaltonetworks.com/CVE-2026-0257
_Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation._
Lyrie Verdict
Lyrie's autonomous detection layer catches active exploitation primitives at machine speed — closing the gap between disclosure and weaponization that traditional defense simply can't cover.
Validated sources
- [1]NVD
- [2]GitHub Advisory
- [3]MITRE
- [4]CISA KEV
Related Articles
active exploitation
🚨 Overhyped vulnerability of the week: Severity inflation in Curl CVE-2026-10536 (Critical 9.8 CVSS, but no security im
1 min read · 1 sources
active exploitation
Black Hat USA 2026 Keynote Announcement!🔥Discover what lies ahead in security innovation. AI-driven systems are transfo
1 min read · 1 sources
active exploitation
CISA: CVE-2026-48939 added to Known Exploited Vulnerabilities — iCagenda iCagenda
1 min read · 3 sources