discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks

Palo Alto says attackers are exploiting a GlobalProtect auth bypass flaw in PAN-OS to breach unpatched VPN devices.

By Lawrence Abrams·May 30·bleepingcomputer.com·2 min read

Intelligence analysis by GPT-5.4 Mini

Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks
Image: bleepingcomputer.com

Palo Alto Networks has raised CVE-2026-0257 to High after confirming limited exploit attempts against unpatched PAN-OS devices. Rapid7 says it saw successful exploitation starting May 17, with attackers using forged authentication override cookies against GlobalProtect gateways.

Why it matters

This is an actively exploited VPN flaw affecting a common enterprise perimeter product, so exposed organizations face real risk of unauthorized access. The CISA KEV listing also puts immediate pressure on federal agencies and other defenders to patch or mitigate quickly.

A company found a bad door in its VPN system, which is like a guarded tunnel into an office network. Attackers can use a fake pass to trick the system into thinking they are allowed in.

Security researchers saw real attacks using this trick. In some cases, the attackers got far enough to reach parts of company networks, which is why the warning got more serious.

The fix is to patch the system right away or turn off the risky feature. It is like changing the lock on a front door and not leaving the spare key under the mat.

Analysis

What happened

Palo Alto Networks says a PAN-OS GlobalProtect authentication bypass flaw, tracked as CVE-2026-0257, is now being actively exploited against unpatched devices. The company had already fixed the issue earlier in the month, but on Friday it updated its advisory to say it had seen limited exploit attempts in the wild and raised the severity from Medium to High.

What the flaw allows

According to Palo Alto, the issue affects the GlobalProtect portal and gateway in PAN-OS software and can let an attacker bypass security restrictions and establish an unauthorized VPN connection. The flaw only applies when devices are configured with authentication override cookies enabled and a specific certificate setup, which is why the original severity was lower.

What researchers saw

Rapid7 said it observed successful exploitation across numerous customers beginning May 17, 2026. Its researchers say the attacks used forged authentication override cookies aimed at the local administrator account. Rapid7 first saw activity from infrastructure hosted by Vultr on May 18, then a second wave on May 21 from Dromatics Systems. In some cases, attackers were able to connect to the device through VPN and reach internal networks, though Rapid7 said many incidents did not progress to a full VPN session.

How the attack works

Rapid7 says the weakness comes from how PAN-OS validates authentication override cookies. The device decrypts the cookie with a configured private key and trusts the result without a signature check. If the same certificate is reused for HTTPS services and for authentication override cookies, an attacker can obtain the public certificate from the HTTPS session and use it to forge a cookie the device accepts. Rapid7 says it built a proof-of-concept that could retrieve the public cert, generate a forged cookie for an arbitrary user, and authenticate without valid credentials.

What defenders should do

Organizations using GlobalProtect should patch immediately. Palo Alto also says admins can mitigate by disabling the authentication override feature or by using a different certificate for that feature and not sharing it with other services on the device. CISA has added CVE-2026-0257 to its Known Exploited Vulnerability catalog and ordered federal agencies to mitigate it by June 1, 2026.

Key points

  • Palo Alto says CVE-2026-0257 is being actively exploited against unpatched PAN-OS GlobalProtect devices.
  • The flaw can let attackers bypass security restrictions and create an unauthorized VPN connection.
  • Rapid7 said it saw successful exploitation starting May 17, 2026, across numerous customers.
  • The issue is tied to how authentication override cookies are validated in PAN-OS.
  • CISA added the flaw to its Known Exploited Vulnerability catalog and set a June 1, 2026 deadline for federal mitigation.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityglobal-newstechpolicy

Author

Lawrence Abrams

Intelligence analysis by

GPT-5.4 Mini

Published

May 30, 2026

Source

bleepingcomputer.com

Share

Topics

securityglobal-newstechpolicy

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…