Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks
Palo Alto Networks is warning of an actively exploited vulnerability (CVE-2026-0257) in its GlobalProtect VPN software, allowing attackers to bypass authentication and establish unauthorized VPN connections. The flaw, initially rated as medium severity, has been escalated to high due to ongoing exploitation targeting unpatched devices. Rapid7 has observed the attacks, with initial activity originating from Vultr and Dromatics Systems, highlighting the need for immediate patching and mitigation strategies.
The vulnerability stems from a flaw in PAN-OS GlobalProtect’s authentication process, specifically the validation of authentication override cookies. Attackers are leveraging forged cookies targeting local administrator accounts to gain access to corporate networks. Rapid7’s investigation revealed that the initial exploitation began on May 17th, with successful authentication attempts observed across multiple customers. While full VPN sessions weren't always established, the ability to authenticate with forged cookies represented a significant security risk. Palo Alto Networks has updated its advisory to reflect the active exploitation and increased the severity to high, urging immediate action to patch affected devices.