24h | 7d | 30d

Overview

  • Palo Alto Networks
  • Cloud NGFW

13 May 2026
Published
30 May 2026
Updated

CVSS v4.0
HIGH (7.8)
EPSS
41.50%

Description

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

Statistics

  • 20 Posts
  • 15 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

CVE-2026-0257: Palo Alto GlobalProtect sotto attacco — cookies bypassano l’autenticazione VPN
#CyberSecurity
insicurezzadigitale.com/cve-20

  • 5
  • 0
  • 0
  • 2h ago
Profile picture fallback

Explotación activa de vulnerabilidad de bypass de autenticación en PAN-OS GlobalProtect (CVE-2026-0257)

blog.elhacker.net/2026/05/expl

  • 0
  • 1
  • 0
  • 21h ago
Profile picture fallback

📰 Actively Exploited PAN-OS Flaw (CVE-2026-0257) Allows VPN Hijack, CISA Adds to KEV

🚨 ACTIVE EXPLOITATION: A PAN-OS flaw (CVE-2026-0257) in GlobalProtect is being exploited to bypass auth & hijack VPNs. CISA has added it to the KEV catalog. Patch now! #CVE #Vulnerability #PaloAltoNetworks

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/pa

  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback

#infosec #vulnerability #vpn

Rapid7 observó la explotación de la vulnerabilidad de omisión de autenticación de PAN-OS GlobalProtect (CVE-2026-0257).

rapid7.com/blog/post/etr-rapid

  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback

A new authentication bypass vulnerability (CVE-2026-0257, CVE-2026-0257) is being actively exploited in the wild. The target: PAN-OS, Prisma Access, VPN. This is not a theoretical risk — attackers are already leveraging it.

This is not the first time a critical authentication bypass has been found in PAN-OS, Prisma Access, VPN.

More at securitycyber.uk
Mastodon: infosec.exchange/@securitycyber
LinkedIn: linkedin.com/in/charlie-collin
Bluesky: bsky.app/profile/securitycyber
Substack: securitycyber.substack.com
Discord: discord.gg/securitycyber

Recommended: hackthebox.com for practice, portswigger.net/web-security for free labs

  • 0
  • 0
  • 2
  • 15h ago
Profile picture fallback

CVE-2026-0257: Palo Alto GlobalProtect sotto attacco — cookies bypassano l’autenticazione VPN

Rapid7 MDR ha documentato due ondate di sfruttamento attivo di CVE-2026-0257, un bypass dell'autenticazione GlobalProtect di Palo Alto Networks. Gli attaccanti forgiano cookie validi usando la chiave pubblica TLS dell'appliance, ottenendo accesso VPN senza credenziali. Un PoC pubblico è già disponibile e la vulnerabilità è nella CISA KEV.

insicurezzadigitale.com/cve-20

  • 0
  • 0
  • 1
  • 3h ago

Bluesky

Profile picture fallback
Palo Alto Networks is warning that hackers are now exploiting a PAN-OS GlobalProtect authentication bypass flaw, tracked as CVE-2026-0257, in attacks attempting to breach corporate networks.
  • 1
  • 5
  • 0
  • 22h ago
Profile picture fallback
Rapid7 observed active exploitation of CVE-2026-0257 in PAN-OS and Prisma Access, where forged GlobalProtect override cookies bypassed login on vulnerable systems. #PaloAlto #GlobalProtect #CVE2026-0257
  • 0
  • 1
  • 0
  • 11h ago
Profile picture fallback
Critical PAN-OS GlobalProtect auth bypass CVE-2026-0257 is being exploited, while ChatGPhish abuses ChatGPT summaries for phishing. Marimo exploit chaining and major data disclosures add to the risk. #GlobalProtect #ChatGPhish #Marimo
  • 0
  • 1
  • 0
  • 5h ago
Profile picture fallback
CVE-2026-0257 is being actively exploited on PAN-OS devices since May 17, 2026, enabling unauthorized VPN access and network exposure.
  • 0
  • 1
  • 0
  • 4h ago
Profile picture fallback
🌟 最新のニュース動向 🌟 🌸 台風6号「チャンミー」が沖縄に猛接近しており、1日から2日に強い勢力で通過の見込みです。速報によると、台風の進路や影響についての情報が続々と更新されています 🌪️。また、小泉防衛相とヘグセス米長官がミサイル共同開発加速で一致したことが報道されました 🚀。 このほか、サイバーセキュリティ動向分析によると、Palo Alto NetworksのPAN-OS GlobalProtect認証バイパス(CVE-2026-0257)が積極的に悪用されているとの報告があります 🚨。金融動向分析では、株式市場が記録更新し、テック主導でS&P500・Nasdaqが上昇したことが注
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
  • 0
  • 0
  • 1
  • 21h ago
Profile picture fallback
Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks https://www.newsbeep.com/ca/705347/ Palo Alto Networks is warning that hackers are now exploiting a PAN-OS GlobalProtect authentication bypass flaw, tracked as CVE-2026-0257,…
  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback
PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation thehackernews.com/2026/05/pan-...
  • 0
  • 0
  • 0
  • 2h ago
Profile picture fallback
CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities - "Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied."
  • 0
  • 0
  • 0
  • 2h ago
Profile picture fallback
📢 CVE-2026-0257 : contournement d'authentification GlobalProtect VPN activement exploité 📝 ## 🔍 Contexte Source : BleepingComputer, publié le 30 mai … https://cyberveille.ch/posts/2026-05-31-cve-2026-0257-contournement-d-authentification-globalprotect-vpn-activement-exploite/ #CISA_KEV #Cyberveille
  • 0
  • 0
  • 0
  • Last hour

Overview

  • FlowiseAI
  • Flowise

21 Apr 2026
Published
22 Apr 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.07%

KEV

Description

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe serialization of stdio commands in the MCP adapter, an authenticated attacker can add an MCP stdio server with an arbitrary command, achieving command execution. The vulnerability lies in a bug in the input sanitization from the “Custom MCP” configuration in http://localhost:3000/canvas - where any user can add a new MCP, when doing so - adding a new MCP using stdio, the user can add any command, even though your code have input sanitization checks such as validateCommandInjection and validateArgsForLocalFileAccess, and a list of predefined specific safe commands - these commands, for example "npx" can be combined with code execution arguments ("-c touch /tmp/pwn") that enable direct code execution on the underlying OS. This vulnerability is fixed in 3.1.0.

Statistics

  • 3 Posts
  • 3 Interactions

Last activity: 12 hours ago

Fediverse

Profile picture fallback

📰 PoC Exploit Released for Critical 9.9 CVSS RCE Flaw in Flowise AI Platform

🔥 CRITICAL RCE in Flowise AI! A 9.9 CVSS flaw (CVE-2026-40933) allows takeover of self-hosted servers with one click. PoC exploit is public. Patch now! #RCE #Vulnerability #AI #Cybersecurity

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/ex

  • 1
  • 0
  • 0
  • 21h ago
Profile picture fallback

🚨 Exploit code for CRITICAL Flowise RCE (CVE-2026-40933) is public. Attackers can execute arbitrary code on self-hosted Flowise servers by tricking users into importing malicious chatflows. Restrict chatflow edits & imports until a patch lands. radar.offseq.com/threat/exploi

  • 1
  • 0
  • 0
  • 16h ago

Bluesky

Profile picture fallback
Obsidian Security published PoC code for CVE-2026-40933, a critical 9.9 RCE in Flowise. Crafted chatflow imports can trigger command execution in self-hosted deployments via Anthropic MCP. #Flowise #MCP #ObsidianSecurity
  • 0
  • 1
  • 0
  • 12h ago

Overview

  • marimo-team
  • marimo

09 Apr 2026
Published
24 Apr 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
82.17%

Description

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands. Unlike other WebSocket endpoints (e.g., /ws) that correctly call validate_auth() for authentication, the /terminal/ws endpoint only checks the running mode and platform support before accepting connections, completely skipping authentication verification. This vulnerability is fixed in 0.23.0.

Statistics

  • 3 Posts
  • 1 Interaction

Last activity: 8 hours ago

Fediverse

Profile picture fallback

⚠️ Attackers used an LLM agent for post-exploitation after breaching a public Marimo notebook via CVE-2026-39987, a pre-auth RCE flaw affecting versions ≤0.20.4.

The intrusion stole cloud credentials, retrieved an SSH key from AWS Secrets Manager, and exfiltrated a PostgreSQL database via eight SSH sessions in under two minutes.

Full report: thehackernews.com/2026/05/atta

  • 0
  • 1
  • 0
  • 8h ago
Profile picture fallback

A new authentication bypass vulnerability (CVE-2026-39987, CVE-2026-39987) is being actively exploited in the wild. The target: LLM, Marimo. This is not a theoretical risk — attackers are already leveraging it.

This is not the first time a critical authentication bypass has been found in LLM, Marimo.

More at securitycyber.uk
Mastodon: infosec.exchange/@securitycyber
LinkedIn: linkedin.com/in/charlie-collin
Bluesky: bsky.app/profile/securitycyber
Substack: securitycyber.substack.com
Discord: discord.gg/securitycyber

Recommended: hackthebox.com for practice, portswigger.net/web-security for free labs

  • 0
  • 0
  • 0
  • 15h ago

Bluesky

Profile picture fallback
Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
  • 0
  • 0
  • 0
  • 23h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 4 Interactions

Last activity: 17 hours ago

Fediverse

Profile picture fallback

oh no socprime.com/blog/cve-2026-480
Fixed version is 26.01, the version of 7z on my Fedora 43 system is 25.01, do I need to upgrade to Fedora 44 to get the fix?

  • 2
  • 2
  • 0
  • 17h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 3 Interactions

Last activity: 5 hours ago

Fediverse

Profile picture fallback

En las últimas 24 horas, se detectaron fallas críticas en Palo Alto GlobalProtect y routers D-Link, mientras una masiva filtración expone datos de 5 millones en Charter Communications; además, crece el debate ético sobre IA y comportamientos violentos, y surgen plataformas para fortalecer habilidades en ciberseguridad con apoyo de inteligencia artificial. Descubre estos y más detalles en el siguiente listado de noticias sobre seguridad informática:

🗞️ ÚLTIMAS NOTICIAS EN SEGURIDAD INFORMÁTICA 🔒
====| 🔥 LO QUE DEBES SABER HOY 31/05/26 📆 |====

🔐 GRAVE VULNERABILIDAD EN PALO ALTO GLOBALPROTECT VPN

Palo Alto Networks alerta sobre un fallo crítico en la autenticación de GlobalProtect que está siendo activamente explotado por atacantes. Este bypass permite acceder ilícitamente a redes corporativas, poniendo en riesgo información sensible y operaciones empresariales. Es fundamental aplicar los parches oficiales inmediatamente para evitar intrusiones masivas.
Descubre cómo proteger tu infraestructura contra esta amenaza aquí 👉 djar.co/3H26z9

📡 FILTRACIÓN MASIVA DE DATOS EN CHARTER COMMUNICATIONS

El grupo de cibercrimen ShinyHunters ha filtrado información confidencial de aproximadamente 5 millones de clientes de Charter Communications tras un intento de extorsión fallido. Esta brecha expone datos personales que pueden ser usados para fraudes y ataques dirigidos. Se recomienda a los usuarios afectar monitorear sus cuentas y reforzar contraseñas.
Conoce los detalles y cómo protegerte ante esta filtración aquí 👉 djar.co/5VT5

🛠 RATCTF: PLATAFORMA GRATUITA PARA ENTRENAR EN CIBERSEGURIDAD

RatCTF ofrece un entorno práctico para aprender y perfeccionar técnicas de ciberataques reales, desde inyección SQL hasta compromiso de Active Directory, mediante laboratorios Docker accesibles y retos de captura de bandera (CTF). Ideal para profesionales y entusiastas que buscan fortalecer sus habilidades defensivas y ofensivas.
Empieza a entrenar tus habilidades de hacking ético aquí 👉 djar.co/6L3mRQ

🚨 VULNERABILIDAD CVE-2026-10206 EN ROUTERS D-LINK DI-8400

Una falla de desbordamiento de pila afecta a dispositivos D-Link DI-8400 en firmware hasta la versión 16.07.26A1, permitiendo la ejecución remota de código. Esta vulnerabilidad representa un riesgo crítico para la seguridad de redes domésticas y corporativas que utilizan estos routers. Actualizar el firmware es urgente para evitar compromisos.
Consulta la información técnica y medidas recomendadas aquí 👉 djar.co/UkiDaP

🤖 ¿DEBERÍAN LAS IA REPORTAR USUARIOS CON COMPORTAMIENTOS VIOLENTOS?

Se debate la responsabilidad ética de las inteligencias artificiales para detectar y alertar sobre usuarios que expresan tendencias violentas. Esta discusión surge a raíz de un caso trágico donde una joven perpetró un tiroteo masivo y posteriormente se suicidó. El debate plantea un equilibrio entre privacidad, prevención y control en sistemas automatizados.
Lee el análisis profundo sobre esta polémica aquí 👉 djar.co/3LhwP

🔍 INTEGRANDO INTELIGENCIA ARTIFICIAL EN EL ENTORNO LABORAL

Denise Dresser y el equipo de OpenAI presentan una transmisión en vivo donde demuestran cómo las empresas están incorporando IA para optimizar equipos, flujos de trabajo y sistemas operativos. Esta tendencia apunta a revolucionar la productividad y seguridad en el ámbito corporativo, destacando el papel clave de la IA en la transformación digital.
Explora esta innovadora aplicación de la IA en el trabajo aquí 👉 djar.co/sV8K8z

  • 2
  • 1
  • 0
  • 5h ago

Overview

  • flippercode
  • WP Maps Pro

29 May 2026
Published
29 May 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.07%

KEV

Description

The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This is due to the wpgmp_temp_access_ajax AJAX action being registered with wp_ajax_nopriv_ and protected only by a nonce check using the fc-call-nonce nonce, which is publicly embedded into every frontend page via wp_localize_script as the nonce field of the wpgmp_local JavaScript object, rendering the check ineffective as an access control mechanism. This makes it possible for unauthenticated attackers to invoke the wpgmp_temp_access_support handler with check_temp=false, which unconditionally creates a new WordPress user with the hardcoded role of administrator via wp_insert_user() and returns a magic login URL that, when visited, calls wp_set_auth_cookie() to fully authenticate the attacker as the newly created administrator, resulting in complete site takeover.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: Last hour

Bluesky

Profile picture fallback
WordPress sites using WP Maps Pro 6.1.0 and earlier face CVE-2026-8732, where attackers can create rogue admin accounts without auth. Fixed in 6.1.1. #WPMapsPro #WordPress #Defiant
  • 0
  • 1
  • 0
  • Last hour

Overview

  • Piotnet
  • Piotnet Addons For Elementor Pro

19 May 2026
Published
19 May 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.08%

KEV

Description

The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_ajax_form_builder' function in all versions up to, and including, 7.1.70. The plugin uses an incomplete extension blacklist that only blocks php, phpt, php5, php7, and exe extensions, while allowing dangerous extensions such as .phar or .phtml to be uploaded. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The exploit can only be exploited if a file field is added to the form.

Statistics

  • 1 Post

Last activity: 5 hours ago

Bluesky

Profile picture fallback
【脆弱性情報】 CVE-2026-4885 Piotnet Addons for Elementor Proの脆弱性について この脆弱性は、WordPress用のPiotnet Addons for Elementor Proプラグインに存在し、すべてのバージョン(7.1.70を含む)でファイルタイプの検証が欠如しているため、
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Fortinet
  • FortiClientEMS

04 Apr 2026
Published
21 Apr 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
41.17%

Description

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

Statistics

  • 1 Post

Last activity: Last hour

Bluesky

Profile picture fallback
📢 CVE-2026-35616 exploitée dans FortiClient EMS pour déployer l'infostealer EKZ déguisé en patch Fortinet 📝 ## 🔍 Contexte En… https://cyberveille.ch/posts/2026-05-31-cve-2026-35616-exploitee-dans-forticlient-ems-pour-deployer-l-infostealer-ekz-deguise-en-patch-fortinet/ #CVE_2026_35616 #Cyberveille
  • 0
  • 0
  • 0
  • Last hour

Overview

  • exifreader

19 May 2026
Published
19 May 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.06%

KEV

Description

This affects versions of the package exifreader before 4.39.0. A crafted image containing an ICC mluc tag can set an attacker-controlled record count together with a zero record size. During parsing, ExifReader repeatedly processes the same record and appends entries to an array without sufficient bounds validation, causing excessive memory growth. In applications that parse attacker-supplied images, this may lead to denial of service through memory exhaustion.

Statistics

  • 1 Post

Last activity: 5 hours ago

Bluesky

Profile picture fallback
【脆弱性情報】 CVE-2026-8813 exifreaderパッケージ(バージョン4.39.0未満)の脆弱性について この脆弱性は、exifreaderパッケージのバージョン4.39.0未満に影響を与えます。攻撃者が作成した画像に含まれるICC mlucタグが、攻撃者が制御するレコード数とゼロのレコードサイズを設定することができます。
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • fermyon
  • spin

08 May 2024
Published
02 Aug 2024
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
0.19%

KEV

Description

Spin is the developer tool for building and running serverless applications powered by WebAssembly. Prior to 2.4.3, some specifically configured Spin applications that use `self` requests without a specified URL authority can be induced to make requests to arbitrary hosts via the `Host` HTTP header. The following conditions need to be met for an application to be vulnerable: 1. The environment Spin is deployed in routes requests to the Spin runtime based on the request URL instead of the `Host` header, and leaves the `Host` header set to its original value; 2. The Spin application's component handling the incoming request is configured with an `allow_outbound_hosts` list containing `"self"`; and 3. In reaction to an incoming request, the component makes an outbound request whose URL doesn't include the hostname/port. Spin 2.4.3 has been released to fix this issue.

Statistics

  • 1 Post

Last activity: 22 hours ago

Fediverse

Profile picture fallback

CVE-2024-32980 - Critical SSRF in Spin. CVSS 9.1. Unpatched. Malicious Host header can redirect self-requests to arbitrary hosts. Update to 2.4.3 or restrict Host header validation immediately. #CVE #Spin #infosec

valtersit.com/cve/CVE-2024-329

  • 0
  • 0
  • 0
  • 22h ago
Showing 1 to 10 of 49 CVEs