PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation
Palo Alto Networks says CVE-2026-0257 is being actively exploited against PAN-OS and Prisma Access, putting VPN access and internal networks at risk.
Intelligence analysis by GPT-5.4 Mini

Palo Alto Networks warned that CVE-2026-0257, an authentication bypass in GlobalProtect, is being exploited on unpatched PAN-OS devices. Rapid7 says it saw successful attacks in multiple customer environments, with some cases leading to VPN access inside the network.
A door meant for workers had a weak lock trick. Some attackers found a way to slip past the check and pretend they were allowed in.
That matters because the door is not inside the building. It sits at the front, where the whole company can be reached.
The fix is to patch it fast or turn off the tricky feature for now, like changing a broken lock before more people test it.
Analysis
What happened
Palo Alto Networks says CVE-2026-0257 affects PAN-OS and Prisma Access when GlobalProtect portal or gateway is configured with authentication override cookies and a specific certificate setup. The flaw lets an attacker bypass authentication and establish an unauthorized VPN connection.
Evidence of exploitation
In an update on May 29, 2026, Palo Alto said it had become aware of limited exploit attempts against unpatched devices without mitigations. Rapid7 reported successful exploitation across multiple customers, with the earliest activity dated May 17 and a second wave on May 21. Rapid7 said both waves appear to come from the same threat actor. In two cases, the second wave led to VPN IP assignment after cookie authentication, which gave the attacker access to the internal network. Rapid7 said it saw no follow-on activity in those environments where a VPN session was established.
Defender response
Palo Alto described the bug as medium severity with a CVSS score of 7.8, but the article makes clear that the real risk is exposure of edge-facing enterprise VPN appliances. The recommended response is urgent patching. As temporary mitigations, organizations can disable the authentication override feature or generate a new certificate used only for that feature.
The article also frames this in a broader pattern of active exploitation against perimeter products, noting another report about weaponized FortiClient EMS flaws being used to deliver credential-stealing malware.
Key points
- Palo Alto Networks says CVE-2026-0257 allows authentication bypass in GlobalProtect portal and gateway setups.
- The company says the flaw is being exploited on unpatched PAN-OS devices without mitigations.
- Rapid7 reported successful exploitation at multiple customers, with activity starting May 17 and a second wave on May 21, 2026.
- In two cases, the attack led to VPN IP assignment and internal network access.
- Recommended mitigations are patching urgently, disabling authentication override, or using a new certificate for that feature.



