Sunday, May 31, 2026
Daily digest
Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks
CVE-2026-0257, an authentication bypass in Palo Alto Networks PAN-OS GlobalProtect, is now being actively exploited to breach corporate networks. Organizations relying on GlobalProtect for remote access — including those protecting CUI in CMMC environments — should apply patches or mitigations immediately and review VPN access logs for anomalous activity.
New CIFSwitch Linux flaw gives root on multiple distributions
A local privilege escalation vulnerability in the Linux kernel, dubbed 'CIFSwitch,' allows attackers to forge CIFS authentication key descriptions and abuse the kernel's key request mechanism to gain root privileges. This affects multiple Linux distributions and is directly relevant to environments running Linux-based hypervisors, containers, or automation platforms such as Nutanix AHV nodes or Ansible control hosts.