Palo Alto VPN bug graduates from advisory to active exploitation
Rapid7 says attackers are actively exploiting a Palo Alto PAN-OS authentication bypass flaw to gain unauthorized GlobalProtect VPN access.
Intelligence analysis by GPT-5.4 Mini

A Palo Alto PAN-OS bug that was first treated as a medium-severity issue is now being actively exploited, according to Rapid7. The flaw can let attackers forge authentication override cookies and open VPN sessions without valid credentials.
A security gate on a company network had a weak spot. Attackers found a way to fake the special pass that lets people through the VPN door.
That means they could get into the network like someone sneaking in with a copied key. They may not have wandered deeper inside yet, but just getting inside is already a big problem.
The fix is to patch the system fast. It is like replacing a broken lock before more people learn how to pick it.
Analysis
What changed
Palo Alto initially disclosed CVE-2026-0257 on May 13 and said it was aware of attempted exploitation but had not seen confirmed malicious use. Rapid7 now says that position no longer holds: it observed successful exploitation across multiple customer environments dating back to at least May 17.
How the flaw is being used
The issue affects PAN-OS deployments that use GlobalProtect authentication override cookies in certain configurations. Rapid7’s analysis says the problem is tied to how PAN-OS trusts those cookies. In some setups, attackers can generate their own cookies and make the firewall accept them as valid. The risk is highest when the same certificate is used for both HTTPS services and authentication override cookies, because that gives attackers what they need to create convincing fakes.
Rapid7 says it validated the attack with proof-of-concept testing and saw multiple waves of activity against vulnerable devices. In some cases, attackers successfully obtained VPN IP addresses and network access. The firm did not observe evidence of lateral movement in the incidents it investigated, but the initial access itself is enough to be a serious concern.
Response from vendors and defenders
The flaw has been added to CISA’s Known Exploited Vulnerabilities catalog, and federal agencies were told to patch or otherwise secure affected systems by June 1. Palo Alto has revised its advisory, raised the severity rating, and applied its highest urgency label. The company says it has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied.
The incident lands less than a month after another Palo Alto emergency, when state-backed attackers were found exploiting CVE-2026-0300 in the PAN-OS User-ID Authentication Portal before patches were widely available. For organizations running GlobalProtect gateways, the choice is again immediate patching or waiting to see whether attackers get there first.
Key points
- Rapid7 says CVE-2026-0257 is being actively exploited against Palo Alto PAN-OS systems.
- The flaw affects GlobalProtect authentication override cookies in specific configurations.
- Attackers may be able to forge cookies and open unauthorized VPN sessions.
- CISA added the bug to its Known Exploited Vulnerabilities catalog.
- Palo Alto raised the severity and urged customers to patch supported releases.
If organizations patch quickly, they can shut down a route that attackers are already using in the wild. The CISA listing and Palo Alto’s updated advisory give defenders a clear signal to prioritize mitigation on exposed gateways.
If unpatched PAN-OS systems stay online, attackers may keep gaining unauthorized VPN access without valid credentials. Even when lateral movement is not immediately seen, that initial foothold can still expose internal networks and create room for follow-on attacks.



