Palo Alto Networks Unit 42 detected active exploitation of PAN-OS vulnerability CVE-2026-0257, an authentication bypass affecting GlobalProtect portal and gateway components. Threat actors are attempting unauthorized VPN access, though minimal post-exploitation activity has been observed so far. Organizations are advised to search logs for specific IP addresses and suspicious device identifiers associated with the attacks and implement available security patches or workarounds.