<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Patch Now: Palo Alto GlobalProtect Auth Bypass Flaw Actively Exploited

Alert: CVE-2026-0257 flaw in PAN-OS VPN exploited. Patch now to prevent unauthorized access and protect your network.
Content Team

A security flaw in Palo Alto Networks' PAN-OS GlobalProtect VPN, tracked as CVE-2026-0257, is being actively exploited — and organizations running unpatched systems are at real risk. Attackers are forging authentication cookies to impersonate legitimate users and gain VPN access without valid credentials.

Palo Alto published its advisory on May 13, but Rapid7 confirmed successful exploitation across multiple customer environments as early as May 17 — including cookie authentication to the local admin account. A second wave on May 21 established working VPN tunnels with internal network access. CISA added the flaw to its Known Exploited Vulnerabilities catalog on May 29.

Palo Alto revised the CVSS score upward from 4.7 to 7.8, moving it from medium to high severity. Rapid7 argues it warrants critical-level urgency regardless — an unauthenticated admin VPN session into your internal network is serious.

Exposure is configuration-dependent: exploitation needs the authentication override feature enabled, with cookie encryption tied to a certificate an attacker can derive the public key from. If you can't patch immediately, disable authentication override or issue a dedicated certificate for it. Fixes span 10.2, 11.1, 11.2, 12.1 and Prisma Access — check the advisory for your branch.

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo