A vulnerability in Palo Alto Networks' GlobalProtect VPN is being actively exploited, allowing attackers to gain unauthorized access to corporate networks. Security firm Rapid7 reports that exploitation began just days after Palo Alto disclosed the issue, which was initially rated as medium-severity.
A busy week in security saw major flaws discovered in Google Chrome, UniFi network devices, and macOS. These vulnerabilities expose users and businesses to data theft, remote attacks, and network takeovers, requiring immediate attention.
Palo Alto Networks has confirmed attackers are actively exploiting a critical authentication bypass vulnerability in its GlobalProtect VPN software. The flaw allows unauthorized access, making immediate patching essential for all affected organizations.
A critical flaw in Check Point VPNs lets attackers bypass passwords and access networks. The vulnerability is being actively exploited, affecting systems that use an older, deprecated security protocol called IKEv1.
A critical flaw in Check Point's enterprise VPNs is being actively used by the Qilin ransomware gang. The vulnerability allows attackers to steal credentials and access corporate networks, requiring immediate patching and investigation.
A critical vulnerability has been found in strongSwan, a popular open-source VPN. Attackers could exploit it remotely to crash systems or potentially run their own code, making immediate patching essential for all users.
Palo Alto Networks warns a medium-severity security flaw in its PAN-OS and Prisma Access products is under active attack. The vulnerability, CVE-2026-0257, allows attackers to bypass authentication and potentially establish unauthorized VPN connections, posing a significant risk to affected networks.