discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Palo Alto VPN bug graduates from advisory to active exploitation

Rapid7 says attackers are actively exploiting a Palo Alto PAN-OS authentication bypass flaw to gain unauthorized GlobalProtect VPN access.

By Carly Page·Jun 1·theregister.com·2 min read

Intelligence analysis by GPT-5.4 Mini

Palo Alto VPN bug graduates from advisory to active exploitation
Image: theregister.com

A Palo Alto PAN-OS bug that was first treated as a medium-severity issue is now being actively exploited, according to Rapid7. The flaw can let attackers forge authentication override cookies and open VPN sessions without valid credentials.

Why it matters

This turns a freshly disclosed VPN weakness into an urgent exposure for organizations running internet-facing Palo Alto gateways. It matters because successful bypass can grant access to internal networks before defenders have time to respond.

A security gate on a company network had a weak spot. Attackers found a way to fake the special pass that lets people through the VPN door.

That means they could get into the network like someone sneaking in with a copied key. They may not have wandered deeper inside yet, but just getting inside is already a big problem.

The fix is to patch the system fast. It is like replacing a broken lock before more people learn how to pick it.

Analysis

What changed

Palo Alto initially disclosed CVE-2026-0257 on May 13 and said it was aware of attempted exploitation but had not seen confirmed malicious use. Rapid7 now says that position no longer holds: it observed successful exploitation across multiple customer environments dating back to at least May 17.

How the flaw is being used

The issue affects PAN-OS deployments that use GlobalProtect authentication override cookies in certain configurations. Rapid7’s analysis says the problem is tied to how PAN-OS trusts those cookies. In some setups, attackers can generate their own cookies and make the firewall accept them as valid. The risk is highest when the same certificate is used for both HTTPS services and authentication override cookies, because that gives attackers what they need to create convincing fakes.

Rapid7 says it validated the attack with proof-of-concept testing and saw multiple waves of activity against vulnerable devices. In some cases, attackers successfully obtained VPN IP addresses and network access. The firm did not observe evidence of lateral movement in the incidents it investigated, but the initial access itself is enough to be a serious concern.

Response from vendors and defenders

The flaw has been added to CISA’s Known Exploited Vulnerabilities catalog, and federal agencies were told to patch or otherwise secure affected systems by June 1. Palo Alto has revised its advisory, raised the severity rating, and applied its highest urgency label. The company says it has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied.

The incident lands less than a month after another Palo Alto emergency, when state-backed attackers were found exploiting CVE-2026-0300 in the PAN-OS User-ID Authentication Portal before patches were widely available. For organizations running GlobalProtect gateways, the choice is again immediate patching or waiting to see whether attackers get there first.

Key points

  • Rapid7 says CVE-2026-0257 is being actively exploited against Palo Alto PAN-OS systems.
  • The flaw affects GlobalProtect authentication override cookies in specific configurations.
  • Attackers may be able to forge cookies and open unauthorized VPN sessions.
  • CISA added the bug to its Known Exploited Vulnerabilities catalog.
  • Palo Alto raised the severity and urged customers to patch supported releases.
The Upside

If organizations patch quickly, they can shut down a route that attackers are already using in the wild. The CISA listing and Palo Alto’s updated advisory give defenders a clear signal to prioritize mitigation on exposed gateways.

The Downside

If unpatched PAN-OS systems stay online, attackers may keep gaining unauthorized VPN access without valid credentials. Even when lateral movement is not immediately seen, that initial foothold can still expose internal networks and create room for follow-on attacks.

Originally reported at

theregister.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritytechpolicyvulnerabilitycisapalo-alto

Author

Carly Page

Intelligence analysis by

GPT-5.4 Mini

Published

Jun 1, 2026

Source

theregister.com

Share

Topics

securitytechpolicyvulnerabilitycisapalo-alto

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…