Skip to content
The Cybersecurity Focus
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
CVEVulnerability

Palo Alto PAN-OS CVE-2026-0257: GlobalProtect Authentication Bypass Under Active Exploit

By ogwatermelon
May 30, 2026 3 Min Read
0
May 30, 2026

CISA has added a critical Palo Alto Networks PAN-OS authentication bypass vulnerability to its Known Exploited Vulnerabilities catalog. CVE-2026-0257 affects GlobalProtect portal and gateway configurations, and it is already being exploited in the wild. Therefore, organizations running affected firewall versions must act quickly to secure their remote access infrastructure.

What Happened: Palo Alto GlobalProtect Authentication Bypass Under Active Attack

Palo Alto Networks disclosed CVE-2026-0257 as an authentication bypass flaw in PAN-OS software. The vulnerability exists when GlobalProtect portal or gateway is configured with authentication override cookies enabled and a specific certificate configuration is present. Consequently, unauthenticated remote attackers can bypass security restrictions and establish unauthorized VPN connections.

Palo Alto Networks confirmed limited exploit attempts against unpatched devices on May 29, 2026. In response, CISA added the flaw to its Known Exploited Vulnerabilities catalog with a mandatory patching deadline of June 1, 2026, for federal agencies. Moreover, private sector organizations should treat this timeline as an urgent signal to audit their GlobalProtect deployments immediately.

Technical Details of the Palo Alto PAN-OS Vulnerability

CVE-2026-0257 is an improper access control vulnerability that undermines the authentication boundary between untrusted internet users and internal VPN resources. The issue specifically manifests when administrators have enabled authentication override cookies for GlobalProtect portal or gateway endpoints.

The vulnerability allows attackers to circumvent the normal authentication flow. Furthermore, successful exploitation grants the attacker an unauthorized VPN session, effectively placing them inside the protected network perimeter without valid credentials.

Affected Configurations and Versions

  • Firewalls with GlobalProtect portal or gateway configured
  • Authentication override cookies enabled in Client Settings
  • A specific certificate configuration present on the device
  • PAN-OS versions 10.2, 11.1, 11.2, and 12.1 (numerous sub-versions)

Palo Alto Networks has released security updates that regenerate authentication override cookies using a more secure method. Therefore, GlobalProtect users will need to re-authenticate once after the upgrade. This one-time requirement is expected behavior after patching.

Business and Operational Impact

The real-world consequences of CVE-2026-0257 extend beyond the firewall itself. An unauthorized VPN connection can provide attackers with a direct tunnel into sensitive corporate networks. Moreover, this access can be leveraged for lateral movement, data exfiltration, or ransomware deployment.

  • Unauthorized network access: Attackers gain VPN connectivity without credentials
  • Lateral movement risk: Compromised VPN sessions enable broader network traversal
  • Data exposure: Internal resources become reachable from an untrusted origin
  • Compliance implications: Failed authentication controls may trigger audit findings
  • Reputation damage: Public disclosure of exploitation can erode customer trust

Mitigation and Recommendations

Organizations should prioritize patching affected PAN-OS instances. However, if immediate patching is not feasible, temporary mitigations are available.

Immediate Actions for Defenders

  1. Apply the latest PAN-OS hotfixes from Palo Alto Networks for affected versions
  2. Verify GlobalProtect portal and gateway configurations for authentication override cookie settings
  3. Review VPN logs for anomalous session establishment without preceding authentication events
  4. Monitor firewall dashboards for unauthorized configuration changes
  5. Alert security teams to the June 1, 2026, CISA KEV deadline

Workarounds Before Patching

Administrators can reduce exposure by reviewing the authentication override settings in GlobalProtect gateway and portal configurations. Disabling the cookie acceptance for authentication override removes one of the prerequisites for exploitation. Furthermore, limiting internet exposure of GlobalProtect portals to known IP ranges via geo-restriction or perimeter controls can reduce the attack surface.

Bottom line: CVE-2026-0257 is actively exploited and carries a federal patching deadline of June 1, 2026. Patch now, audit your GlobalProtect authentication settings, and monitor VPN logs for unauthorized sessions.

Incident Summary

CVE ID / Incident: CVE-2026-0257
Affected Systems: Palo Alto Networks PAN-OS firewalls with GlobalProtect portal or gateway configured
Disclosure Date: May 29, 2026
Patch Status: Updates available; CISA KEV due date June 1, 2026
Severity: Critical (authentication bypass, unauthorized VPN access)
Exploitation: Limited active exploitation confirmed by vendor

References

  1. Palo Alto Networks, “CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities,” May 2026, https://security.paloaltonetworks.com/CVE-2026-0257, accessed May 30, 2026.
  2. CISA, “Known Exploited Vulnerabilities Catalog: CVE-2026-0257,” May 29, 2026, https://www.cisa.gov/known-exploited-vulnerabilities-catalog, accessed May 30, 2026.
  3. National Vulnerability Database, “NVD – CVE-2026-0257,” https://nvd.nist.gov/vuln/detail/CVE-2026-0257, accessed May 30, 2026.

Tags:

CVEVulnerability
Author

ogwatermelon

Follow Me
Other Articles
Previous

Unpatched Gogs Zero-Day Enables Remote Code Execution on Git Servers

Next

CIFSwitch Linux Flaw Grants Root Access on Major Distros

AI Botnet Breach CVE Exploit Hack Incident Linux Malware Network Ransomware supply chain Vulnerability Windows World Zero Day

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Archives

  • July 2026
  • June 2026
  • May 2026

Categories

  • AI
  • BotNet
  • Breach
  • CVE
  • exploit
  • Hack
  • Incident
  • Linux
  • Malware
  • Phishing
  • Ransomware
  • supply-chain
  • Uncategorized
  • Vulnerability
  • Windows
  • World
  • Zero Day
Copyright 2026 — The Cybersecurity Focus. All rights reserved.