Two vulnerabilities currently being actively exploited in the wild pose serious risks to businesses using common VPN and network infrastructure products. Alongside these, US cybersecurity authorities added new entries to their known-exploited vulnerabilities list this week, with patch deadlines now due.
- Palo Alto GlobalProtect VPN (CVE-2026-0257): Attackers are bypassing authentication on Palo Alto VPN gateways and gaining unauthorised access to business networks without valid credentials. The attack uses forged authentication cookies to impersonate legitimate users. Palo Alto has issued patches, but unpatched devices remain at risk. If your business uses Palo Alto for remote access VPN, ensure your IT provider has applied this update urgently. (Source: The Hacker News)
- Cisco SD-WAN Zero-Day (CVE-2026-20245): Cisco has confirmed a seventh SD-WAN product vulnerability being actively exploited in 2026. An attacker with valid network admin credentials can execute commands as root, the highest privilege level on the system. No patch is currently available. If your business uses Cisco Catalyst SD-WAN, contact your IT provider to check your exposure. (Source: SecurityWeek)
- CISA Patch Deadlines: The US Cybersecurity and Infrastructure Security Agency added a Joomla Content Editor access control vulnerability (CVE-2026-48907) to its known-exploited list on June 16. Today is also the patch deadline for a LiteSpeed cPanel privilege escalation flaw (CVE-2026-54420, severity score 8.5/10) that allows attackers to gain root access on shared hosting servers. If your website runs on cPanel-based hosting, check with your host that this has been addressed. (Source: CISA)
We recommend confirming with your IT provider that firewall and VPN firmware is current and that public-facing infrastructure has been assessed against these active threats.