Palo Alto Networks
PAN-OS and GlobalProtect vulnerabilities affecting Palo Alto Networks firewalls — perimeter devices where a single command-injection flaw can mean full network compromise.
PAN-OS GlobalProtect authentication bypass
PAN-OS GlobalProtect portal and gateway authentication bypass allowing an unauthorized VPN connection under a specific authentication-override-cookie and certificate configuration. Actively exploited by Qilin ransomware.
Palo Alto Networks PAN-OS GlobalProtect Command Injection Zero-Day
A command-injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS allows an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Exploited in the wild as a zero-day before a patch was available.

Qilin exploits PAN-OS GlobalProtect CVE-2026-0257
Arctic Wolf documents Qilin ransomware breaching networks through a two-month-old PAN-OS GlobalProtect authentication bypass, and assesses with moderate confidence that intrusions are ongoing.

PAN-OS GlobalProtect Zero-Day Gave Attackers Root
CVE-2024-3400, a maximum-severity command-injection flaw in Palo Alto Networks' PAN-OS GlobalProtect feature, was exploited in the wild before a patch existed — handing attackers root access to the perimeter firewall.