news.mlab.sh
Back to the feed
vulnerability

Patch Now: Another Palo Alto Auth Bypass Bug Under Active Exploit

Critical
Summary

A vulnerability in Palo Alto Networks' PAN-OS GlobalProtect VPN technology, tracked as CVE-2026-0257, is currently being actively exploited. Attackers are leveraging a configuration flaw to bypass authentication and gain unauthorized VPN access to networks. Due to the ongoing exploitation and potential for significant impact, experts are urging organizations to apply the vendor's patch immediately, despite the initial CVSS score of 7.8.

The vulnerability stems from a feature called "authentication override" within the GlobalProtect portal and gateway. This allows the VPN to issue cookies to authenticated users, enabling them to bypass re-authentication. However, the flaw arises when the same certificate is used for both the GlobalProtect portal/gateway's HTTPS service and the encryption/decryption of these authentication override cookies. Rapid7 researchers discovered that under specific configurations, the system trusts these decrypted cookies without proper verification, allowing attackers to forge cookies and establish authenticated sessions.

Successful exploitation has been observed across numerous customer environments, with attackers using forged cookies to impersonate legitimate users and gain access to internal networks. A second wave of attacks occurred on May 21st, with some attackers assigned VPN addresses and gaining internal network access. Rapid7 is urging organizations to treat this as a critical vulnerability, emphasizing the potential for significant impact due to the nature of an unauthenticated VPN session.

This incident follows a similar exploit targeting a PAN-OS authentication bypass flaw (CVE-2025-0108) earlier this year, highlighting the importance of timely patching and security vigilance. Palo Alto Networks has released a patch for CVE-2026-0257, and organizations are advised to apply it urgently.

Read the full article at Dark Reading