LmCast :: Stay tuned in

Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks

Recorded: May 30, 2026, 6:03 p.m.

Original Summarized

Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks

News

Featured
Latest

California AG sues 23andMe over 2023 breach exposing health data

US charges Google security engineer with Polymarket insider trading

Charter Communications data breach affects 4.9 million accounts

GreyVibe hackers use ChatGPT, Gemini to power cyberattacks

New CIFSwitch Linux flaw gives root on multiple distributions

One more day to grab AdGuard’s VPN + ad blocker package for just $40

ChatGPT share links abused to host fake outage pages to deliver malware

California AG sues 23andMe over 2023 breach exposing health data

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityPalo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks

Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks

By Lawrence Abrams

May 30, 2026
02:02 PM
0

Palo Alto Networks is warning that hackers are now exploiting a PAN-OS GlobalProtect authentication bypass flaw, tracked as CVE-2026-0257, in attacks attempting to breach corporate networks.
The company fixed the CVE-2026-0257 flaw earlier this month, warning that it could be used to establish unauthorized VPN connections on the device.
"GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection," reads Palo Alto's advisory.
The flaw received a Medium severity rating because it requires devices to be configured with authentication override cookies enabled and a specific certificate configuration.
However, on Friday, Palo Alto Networks updated the advisory to warn that the flaw was now being actively exploited in attacks against unpatched devices, raising the severity rating to High.
"Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied," reads the update.
This update comes after Rapid7 warned that it had observed the flaw being exploited against numerous customers starting on May 17.
"Rapid7 MDR identified successful exploitation across numerous customers, however we did not observe any indication of successful lateral movement from the devices. The earliest date for observed exploitation was May 17, 2026," explains Rapid7.
"As of May 29, 2026,  this vulnerability has been added to the CISA KEV."
According to Rapid7, the attacks began with hackers authenticating to GlobalProtect gateways using forged authentication override cookies that targeted the local administrator account.
The company first observed exploitation on May 18 from infrastructure hosted by Vultr, with a second wave of attacks detected on May 21 originating from Dromatics Systems.
In some cases, attackers were able to connect to the device via VPN using forged cookies, granting them access to internal networks. However, Rapid7 says that in many incidents, even though the appliance accepted the forged cookie, they were unable to establish a full VPN session.
Rapid7's investigation into affected customers found that the impacted devices had GlobalProtect authentication override cookies enabled and were configured in a way that allowed attackers to forge valid authentication cookies.
The researchers say the flaw stems from PAN-OS's validation of authentication override cookies.
A GlobalProtect VPN device decrypts these types of cookies using a configured private key and then trusts the decrypted contents without performing any signature verification.
If the same certificate is reused for both HTTPS services and authentication override cookies, attackers can obtain the corresponding public key via the HTTPS session and then use it to create forged cookies that the device will accept as legitimate.
Rapid7 developed a proof-of-concept exploit that demonstrates how an attacker can retrieve the public certificates exposed by a GlobalProtect portal or gateway, generate a forged authentication override cookie for an arbitrary user, and authenticate without knowing valid credentials. Using this PoC, the researchers successfully authenticated to an unpatched GlobalProtect gateway.
Organizations using GlobalProtect VPN devices should immediately install the latest security updates to patch the flaws.
Admins can also mitigate the flaw by turning off the authentication override feature or utilizing a different certificate for this feature and not sharing it with other services on the device.
CISA has now added the flaw to its Known Exploited Vulnerability catalog, ordering federal agencies to mitigate the flaw by June 1, 2026.

The Validation Gap: Automated Pentesting Answers One Question. You Need Six.

Automated pentesting tools deliver real value, but they were built to answer one question: can an attacker move through the network? They were not built to test whether your controls block threats, your detection rules fire, or your cloud configs hold.This guide covers the 6 surfaces you actually need to validate.
Download Now

Related Articles:
Hackers exploit FortiClient EMS flaw to push infostealer malwareHackers bypass SonicWall VPN MFA due to incomplete patchingHackers exploit auth bypass flaw in Burst Statistics WordPress pluginPalo Alto Networks firewall zero-day exploited for nearly a monthPalo Alto Networks warns of firewall RCE zero-day exploited in attacks

Actively Exploited
Authentication Bypass
CVE-2026-0257
Palo Alto Networks
PAN-OS
VPN
Vulnerability

Lawrence Abrams
Lawrence Abrams is the owner and Editor in Chief of BleepingComputer.com. Lawrence's area of expertise includes Windows, malware removal, and computer forensics. Lawrence Abrams is a co-author of the Winternals Defragmentation, Recovery, and Administration Field Guide and the technical editor for Rootkits for Dummies.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

ChatGPT share links abused to host fake outage pages to deliver malware

Anthropic confirms Claude Mythos-class models will roll out to the public

Windows 11 KB5089573 update released with performance improvements

Sponsor Posts

33% Rise in Healthcare Credential Theft in 2025: What you need to know

Overdue a password health-check? Audit your Active Directory for free

#1 MSP Benchmark report 2026: Insights from 1,000+ MSPs on growth, security, artificial intelligence, and key 2026 trends.

AI is a data-breach time bomb: Read the new report

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

Palo Alto Networks has issued a warning regarding an authentication bypass flaw, tracked as CVE-2026-0257, affecting the PAN-OS GlobalProtect feature, which is currently being exploited in attacks aimed at breaching corporate networks. The vulnerability allows an attacker to bypass existing security restrictions and establish unauthorized Virtual Private Network connections through the GlobalProtect portal and gateway. Although the flaw was initially rated as Medium severity because it required specific configurations regarding authentication override cookies and certificate settings, Palo Alto Networks subsequently escalated the advisory to High severity after determining that the vulnerability was actively being exploited against unpatched devices.

Rapid7 observed successful exploitation attempts across numerous customer environments, with the earliest reported exploitation detected on May 17, 2026. The attacks involved hackers successfully authenticating to the GlobalProtect gateways by using forged authentication override cookies that targeted the local administrator account. While investigations indicated that in many instances the appliance accepted the forged cookie, attackers were often unable to establish a full VPN session, the potential for unauthorized access was clearly demonstrated. The research indicates that the flaw originates from PAN-OS's handling of authentication override cookies; specifically, the device decrypts these cookies using a configured private key and trusts the decrypted contents without performing necessary signature verification. A critical aspect of the flaw is the potential for certificate reuse: if the same certificate is used for both HTTPS services and authentication override cookies, attackers can leverage the HTTPS session to obtain the corresponding public key, which they then use to create forged cookies that the device will accept as legitimate credentials.

Researchers developed a proof-of-concept exploit demonstrating this mechanism. This exploit illustrates how an attacker can retrieve public certificates exposed by a GlobalProtect portal or gateway, generate forged authentication override cookies for any arbitrary user, and successfully authenticate to an unpatched gateway without possessing valid credentials. This finding highlights a fundamental weakness in the trust model regarding these cookies. Consequently, organizations utilizing GlobalProtect VPN devices are strongly advised to immediately apply the latest security updates to patch these flaws. Furthermore, administrators can implement mitigations by either disabling the authentication override feature entirely or by configuring the system to utilize a different certificate, ensuring that certificates used for authentication override are not shared across other services on the device. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerability catalog, mandating that federal agencies mitigate the flaw by June 1, 2026.