Patch Now: Palo Alto GlobalProtect Auth Bypass Flaw Actively Exploited
Want more insights like this?
A security flaw in Palo Alto Networks' PAN-OS GlobalProtect VPN, tracked as CVE-2026-0257, is being actively exploited — and organizations running unpatched systems are at real risk. Attackers are forging authentication cookies to impersonate legitimate users and gain VPN access without valid credentials.
Palo Alto published its advisory on May 13, but Rapid7 confirmed successful exploitation across multiple customer environments as early as May 17 — including cookie authentication to the local admin account. A second wave on May 21 established working VPN tunnels with internal network access. CISA added the flaw to its Known Exploited Vulnerabilities catalog on May 29.
Palo Alto revised the CVSS score upward from 4.7 to 7.8, moving it from medium to high severity. Rapid7 argues it warrants critical-level urgency regardless — an unauthenticated admin VPN session into your internal network is serious.
Exposure is configuration-dependent: exploitation needs the authentication override feature enabled, with cookie encryption tied to a certificate an attacker can derive the public key from. If you can't patch immediately, disable authentication override or issue a dedicated certificate for it. Fixes span 10.2, 11.1, 11.2, 12.1 and Prisma Access — check the advisory for your branch.
Source: Dark Reading