Palo Alto Networks patched a critical authentication bypass vulnerability in its PAN-OS GlobalProtect feature in May 2026 after confirming it was being actively exploited. The flaw, designated CVE-2026-0257, allows attackers to bypass security restrictions and establish unauthorized VPN connections on affected devices.
"GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection," reads Palo Alto's advisory. The company initially rated the vulnerability as Medium severity because it requires devices to have authentication override cookies enabled along with a specific certificate configuration. However, Palo Alto updated its advisory on Friday to elevate the severity to High after detecting active exploitation.
"Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied," reads the update. Cybersecurity firm Rapid7 observed successful exploitation across numerous customers, with the earliest confirmed incident occurring on May 17, 2026. "Rapid7 MDR identified successful exploitation across numerous customers, however we did not observe any indication of successful lateral movement from the devices. The earliest date for observed exploitation was May 17, 2026," explains Rapid7.
The attacks began when hackers authenticated to GlobalProtect gateways using forged authentication override cookies targeting the local administrator account. In some cases, attackers connected via VPN using these forged cookies, gaining access to internal networks. However, in many incidents, even though the appliance accepted the forged cookie, attackers failed to establish a full VPN session.
Rapid7’s investigation found that impacted devices had GlobalProtect authentication override cookies enabled and used certificate configurations that allowed attackers to forge valid authentication cookies. The vulnerability stems from PAN-OS’s validation process, which decrypts cookies using a private key but skips signature verification. If the same certificate is used for both HTTPS services and authentication override cookies, attackers can retrieve the public key via HTTPS and generate forged cookies the device treats as legitimate.
On May 29, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-0257 to its Known Exploited Vulnerabilities catalog and ordered federal agencies to apply fixes by June 1, 2026. Organizations using GlobalProtect are urged to install the latest security updates immediately. Administrators can also mitigate the flaw by disabling the authentication override feature or assigning it a certificate not shared with other device services.
forum Comments (0)
No comments yet. Be the first to comment.