Palo Alto GlobalProtect CVE-2026-0257: the second 2026 network-perimeter auth bypass
CVE-2026-0257 is a CVSS 7.8 auth bypass in PAN-OS GlobalProtect. When the cert encrypting the override cookie is shared with another feature, an unauthenticated attacker can forge it and open a VPN session. Some victims got full internal-network access.