A vulnerability in Palo Alto Networks' PAN-OS, the software that runs the company's firewalls, is being exploited in the wild. Tracked as CVE-2026-0257, the flaw lets an attacker bypass security restrictions and establish an unauthorised VPN connection through a GlobalProtect gateway. The US Cybersecurity and Infrastructure Security Agency (CISA) has added it to its Known Exploited Vulnerabilities catalog and set a 1 June remediation deadline for federal civilian agencies.
What the flaw does
GlobalProtect is the VPN that lets remote staff reach an internal network. A bypass of the VPN is serious: it gives an attacker a foothold inside the network perimeter without needing valid credentials. Active exploitation has been confirmed by both the vendor and an independent managed-detection provider, and the attackers are reported to have working tooling aimed at unpatched gateways. A firewall is meant to be the control. Here it is the way in.
Why the deadline matters beyond Washington
CISA's deadline binds US federal agencies, but the catalogue is read as a global to-do list. A listing means exploitation is real and confirmed, not theoretical. Any organisation running an exposed GlobalProtect gateway should treat the federal date as its own. Edge devices like firewalls and VPN concentrators have become the preferred entry point for both criminal and state-backed crews, precisely because they sit at the boundary and are often patched late.
What to do
Apply Palo Alto's fixed PAN-OS release. Where patching has to wait, restrict GlobalProtect exposure to known address ranges and watch authentication logs for VPN sessions that do not match a real user. Treat any internet-facing management interface as a liability until the update is confirmed in place. The pattern this year is consistent: the bug is on the box guarding the door.
Note: This is defensive reporting for patch prioritisation. No exploit code or proof-of-concept is reproduced here.
The vendor and the regulators never agreed on how bad it was
This flaw is a good illustration of a wider point: a severity score is a claim made under a framework, not a fact about a vulnerability.
Palo Alto Networks rates CVE-2026-0257 7.8 High under CVSS-BT using version 4.0 of the standard. The National Vulnerability Database and Singapore's Cyber Security Agency both list a CVSS v3.1 base score of 9.1 Critical. Neither is wrong. They are different versions of the scoring system, and one of them incorporates threat intelligence about exploitation while the other describes the flaw in the abstract.
A defender reading a vendor bulletin and a national advisory on the same morning gets conflicting ratings — High from one, Critical from the other — for the same bug on the same appliance. Any organisation that triages by severity band — and most do, because that is what the ticketing system sorts on — will queue this differently depending on which document it read first.
The practical rule this argues for is to triage exposed edge devices on exploitation status rather than on score. This flaw's presence in the CISA catalogue means exploitation is confirmed — a harder signal than any CVSS score.
Exploitation ran ahead of the paperwork
The disclosure timeline is not what a defender would hope to see.
Palo Alto published its advisory on 13 May and updated it on 29 May, after becoming aware of limited exploit attempts against unpatched gateways with no mitigations applied. CISA added the flaw to its catalogue the same day, setting the 1 June deadline. Singapore's CSA issued its own alert on 31 May.
Independent detection work placed attackers forging VPN session cookies against this flaw from around 17 May — twelve days before the vendor's update, and twelve days before the catalogue entry that started the federal clock. The window in which an exposed gateway was being attacked but not yet listed anywhere a vulnerability programme polls was almost two weeks long.
That is the same shape as the GeoServer disclosure in August, where scanning began within hours of a public post and before any catalogue entry existed. A remediation deadline keyed to a catalogue listing is, by definition, a lagging indicator.
What our later reporting added
Two subsequent pieces followed this one and carry the detail a reader chasing the incident will want.
Our report on Singapore's CSA rating the flaw critical covers the divergence from Palo Alto's own rating and the cookie-forging activity in the wild. Our report on Palo Alto confirming active exploitation sets out the affected versions, the fixes and the interim mitigations for teams that cannot patch immediately.
Prisma Access, the cloud-delivered service, is in scope alongside on-premises PAN-OS. An organisation that concluded it was unaffected because it runs no physical firewall should check that assumption.