Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks
Palo Alto says attackers are exploiting a GlobalProtect auth bypass flaw in PAN-OS to breach unpatched VPN devices.
Intelligence analysis by GPT-5.4 Mini

Palo Alto Networks has raised CVE-2026-0257 to High after confirming limited exploit attempts against unpatched PAN-OS devices. Rapid7 says it saw successful exploitation starting May 17, with attackers using forged authentication override cookies against GlobalProtect gateways.
A company found a bad door in its VPN system, which is like a guarded tunnel into an office network. Attackers can use a fake pass to trick the system into thinking they are allowed in.
Security researchers saw real attacks using this trick. In some cases, the attackers got far enough to reach parts of company networks, which is why the warning got more serious.
The fix is to patch the system right away or turn off the risky feature. It is like changing the lock on a front door and not leaving the spare key under the mat.
Analysis
What happened
Palo Alto Networks says a PAN-OS GlobalProtect authentication bypass flaw, tracked as CVE-2026-0257, is now being actively exploited against unpatched devices. The company had already fixed the issue earlier in the month, but on Friday it updated its advisory to say it had seen limited exploit attempts in the wild and raised the severity from Medium to High.
What the flaw allows
According to Palo Alto, the issue affects the GlobalProtect portal and gateway in PAN-OS software and can let an attacker bypass security restrictions and establish an unauthorized VPN connection. The flaw only applies when devices are configured with authentication override cookies enabled and a specific certificate setup, which is why the original severity was lower.
What researchers saw
Rapid7 said it observed successful exploitation across numerous customers beginning May 17, 2026. Its researchers say the attacks used forged authentication override cookies aimed at the local administrator account. Rapid7 first saw activity from infrastructure hosted by Vultr on May 18, then a second wave on May 21 from Dromatics Systems. In some cases, attackers were able to connect to the device through VPN and reach internal networks, though Rapid7 said many incidents did not progress to a full VPN session.
How the attack works
Rapid7 says the weakness comes from how PAN-OS validates authentication override cookies. The device decrypts the cookie with a configured private key and trusts the result without a signature check. If the same certificate is reused for HTTPS services and for authentication override cookies, an attacker can obtain the public certificate from the HTTPS session and use it to forge a cookie the device accepts. Rapid7 says it built a proof-of-concept that could retrieve the public cert, generate a forged cookie for an arbitrary user, and authenticate without valid credentials.
What defenders should do
Organizations using GlobalProtect should patch immediately. Palo Alto also says admins can mitigate by disabling the authentication override feature or by using a different certificate for that feature and not sharing it with other services on the device. CISA has added CVE-2026-0257 to its Known Exploited Vulnerability catalog and ordered federal agencies to mitigate it by June 1, 2026.
Key points
- Palo Alto says CVE-2026-0257 is being actively exploited against unpatched PAN-OS GlobalProtect devices.
- The flaw can let attackers bypass security restrictions and create an unauthorized VPN connection.
- Rapid7 said it saw successful exploitation starting May 17, 2026, across numerous customers.
- The issue is tied to how authentication override cookies are validated in PAN-OS.
- CISA added the flaw to its Known Exploited Vulnerability catalog and set a June 1, 2026 deadline for federal mitigation.



