June 15, 2026
The Palo Alto VPN vulnerability CVE-2026-0257 allows unauthenticated attackers to forge authentication override cookies and bypass GlobalProtect completely. Rapid7 confirmed active exploitation from May 17, 2026. CISA listed it in the KEV catalog. Patch all firewalls now.






