5 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
Initial Access TA0001
T1133External Remote Services×1
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.
T1036.005Masquerading: Match Legitimate Resource Name or Location×1
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.
An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials. Web applications and services often use session cookies as an authentication token after a user has authenticated to a website.
Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port, vulnerability, and/or wordlist scans using tools that are brought onto a system.
Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.
First disclosed in May and KEV-listed on 2026-05-29, the GlobalProtect portal/gateway authentication bypass moved into a confirmed exploitation wave this week. Unit 42 observed active exploitation by an unidentified actor attempting to access GlobalProtect, with Arctic Wolf reporting increasing exploitation volume and NCSC-CH refreshing its advisory on 2026-06-16 (Unit 42; daily 06-17). Notably, Unit 42 states no post-access lateral movement had been identified as of its analysis — so the current operational signal is unauthorised VPN session establishment, not yet confirmed downstream compromise. Patch to the fixed PAN-OS trains, and hunt GlobalProtect logs for authentications that bypass the expected portal flow.
Palo Alto Networks Unit 42 has observed active exploitation of PAN-OS vulnerability CVE-2026-0257 by an unidentified threat actor attempting to access GlobalProtect.
No post-access behavior or lateral movement has been identified as of this time.
Authentication override cookies in PAN-OS GlobalProtect are encrypted using the portal or gateway certificate. When that same certificate is shared with another service (most commonly the HTTPS service — a non-default but operationally common configuration), an unauthenticated attacker can extract the certificate's public key from the HTTPS service and forge valid authentication override cookies, obtaining a full VPN session without credentials (Palo Alto Networks PSIRT, 2026-05-29). Root cause: CWE-565 (Reliance on Cookies Without Validation and Integrity Checking). CVSS 4.0 = 7.8 HIGH (Exploit Maturity: ATTACKED). Affected: PAN-OS 10.2.x, 11.1.x, 11.2.x, 12.1.x; Prisma Access 10.2 and 11.2; Panorama and Cloud NGFW are not affected. Rapid7 MDR observed two exploitation waves — 18 May from Vultr-hosted infrastructure, 21 May from Dromatics Systems IP space — both sharing a deliberately spoofed, easily-recognisable MAC address pattern and machine names GP-CLIENT (Linux) and DESKTOP-GP01 (Windows), indicating a single actor (Rapid7 ETR, 2026-05-29). A public PoC is available. CISA added CVE-2026-0257 to KEV on 29 May. Detection: GlobalProtect connection logs with cookie-based auth-override events sourced from unexpected IP blocks; sessions authenticating without prior MFA web-step; PCAP anomaly of identical MAC across geographically-disparate sessions. Immediate remediation: upgrade to fixed PAN-OS versions (10.2.7-h34+, 11.1.4-h33+, 11.2.4-h17+, 12.1.4-h6+ and subsequent maintenance releases — full version table in the vendor advisory); or disable authentication override cookies; or assign an exclusive certificate to GlobalProtect not shared with any other service.
Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied.
Rapid7 MDR observed a second wave of exploitation on May 21st, and due to consistent MAC address, they believe both waves of exploitation are likely from the same threat actor.
Rapid7
UPDATE (originally covered 2026-05-30): Unit 42's 9 June update on CVE-2026-0257 confirms that a limited number of probed PAN-OS GlobalProtect devices had attacker-established, gateway-connected VPN sessions, moving this from "exploit attempts observed" to confirmed successful exploitation (Unit …
UPDATE (originally covered 2026-05-30): Palo Alto's Unit 42 confirms an active exploitation campaign against the GlobalProtect cookie authentication-bypass (CVE-2026-0257) running since approximately late May (Unit 42, 2026-06-09).
Unit 42's 9 June update on CVE-2026-0257 confirms that a limited number of probed PAN-OS GlobalProtect devices had attacker-established, gateway-connected VPN sessions, moving this from "exploit attempts observed" to confirmed successful exploitation (Unit 42, 2026-06-09). The bug (CWE-565, reliance on a cookie without integrity checking) lets an attacker extract the encryption certificate's public key from the TLS handshake and forge authentication-override cookies when that certificate is shared with another function; Rapid7 dates successful exploitation to 17 May from low-cost hosting IPs (Rapid7, 2026-05-29).
Affected: PAN-OS 10.2/11.1/11.2/12.1 and Prisma Access where authentication override is enabled with a shared certificate; patched in 12.1.7+, 11.2.12+, 11.1.15+, 10.2.18-h6+ and corresponding Prisma builds (Palo Alto Networks, 2026-06-03). Patch, then force one re-authentication so override cookies regenerate; as a workaround disable authentication override or assign it a dedicated certificate. Hunt GlobalProtect gateway logs for auth-method=cookie from unexpected source IPs.
Palo Alto's Unit 42 confirms an active exploitation campaign against the GlobalProtect cookie authentication-bypass (CVE-2026-0257) running since approximately late May (Unit 42, 2026-06-09). The flaw (CWE-565) decrypts an authentication-override cookie without any signature verification, letting an attacker forge a session and establish a VPN tunnel without credentials when the override feature is enabled (Palo Alto Networks PSIRT).
Arctic Wolf's telemetry documents post-exploitation consistent with Impacket tooling — SMB lateral movement, anonymous NTLM logon, share enumeration and domain-user discovery — across insurance, finance, manufacturing, education, engineering and healthcare targets in North America and Europe (Arctic Wolf, 2026-06-11). NCSC-CH refreshed its Security Hub advisory on 2026-06-16 to flag the Unit 42 confirmation (NCSC-CH Security Hub, 2026-06-16). Defenders: disable "Authentication Override" if not required, patch to fixed PAN-OS builds, and audit sessions since late May for Impacket-pattern lateral movement (EID 4624 Type 3 from unexpected IPs, SMB enumeration EID 5140/5145).
Background. GlobalProtect is Palo Alto Networks' SSL-VPN solution embedded in PAN-OS and widely deployed as the internet-facing VPN gateway for enterprise and government networks. The authentication override feature, introduced to support certain SSO and clientless configurations, allows a GlobalProtect portal or gateway to issue signed cookies that bypass the normal MFA/SAML authentication flow on subsequent connections — trading off per-session authentication strength for session-persistence smoothness. Palo Alto's own security advisories (AA23-250A, AA24-075A) have repeatedly highlighted GlobalProtect as a target surface; this vulnerability is the most directly exploitable advisory in that series.
Vulnerability mechanics. CVE-2026-0257 is classified CWE-565 (Reliance on Cookies Without Validation and Integrity Checking). When authentication override is enabled and the GlobalProtect portal or gateway shares an X.509 certificate with another co-hosted service — most commonly the HTTPS management or captive-portal service — that certificate's public key is retrievable by any external party simply by connecting to the HTTPS service and inspecting the TLS handshake. Palo Alto's auth-override cookie uses that same certificate to sign and encrypt session tokens. An attacker who extracts the public key can derive the encryption material needed to mint a valid authentication override cookie, then present it to the GlobalProtect service to authenticate as any user without possessing the user's credentials. The attack requires no prior foothold; the only pre-condition is network reachability to the GlobalProtect portal or gateway and the presence of a shared certificate — a configuration that has historically been documented in Palo Alto's own deployment guides as a shortcut for certificate management.
Exploitation pattern. Rapid7 MDR observed two exploitation waves (Rapid7 ETR, 2026-05-29). Wave 1 (18 May): sourced from Vultr-hosted infrastructure, machine name GP-CLIENT (Linux). Wave 2 (21 May): sourced from Dromatics Systems IP space, machine name DESKTOP-GP01 (Windows). Both used a deliberately spoofed, easily-recognisable MAC address pattern — suggesting deliberate source-normalisation to defeat MAC-based network anomaly detection. Rapid7 observed successful VPN session establishment but no confirmed lateral movement in the monitored environments. A public PoC (github.com/sfewer-r7/CVE-2026-0257) was released on 29 May, the same day CISA added the CVE to KEV. The gap between the exploitation waves (18 and 21 May) and the PoC/KEV date (29 May) implies the actor possessed private pre-disclosure knowledge of the vulnerability.
MITRE ATT&CK mapping. Initial access: T1133 (External Remote Services — GlobalProtect VPN endpoint). Credential access: T1539 (Steal Web Session Cookie, here applied to auth-override cookie forging rather than theft). Defence evasion: T1036.005 (Masquerading: Match Legitimate Name or Location — spoofed machine name DESKTOP-GP01). Lateral movement: T1021.001 (Remote Services: Remote Desktop Protocol — expected next step once inside the network segment); T1046 (Network Service Discovery — attacker-controlled GP-CLIENT enumerating accessible segments).
Affected and patched versions. Affected: PAN-OS 10.2.x < 10.2.7-h34 (and maintenance tracks), 11.1.x < 11.1.4-h33, 11.2.x < 11.2.4-h17, 12.1.x < 12.1.4-h6. Not affected: Panorama, Cloud NGFW, Prisma SD-WAN, PA-Series managed by Panorama with no local GP config, PAN-OS < 10.2.x (EOL). Fixed: the full version matrix per PAN-OS maintenance branch is in the vendor advisory. Prisma Access 10.2 and 11.2: Palo Alto is rolling fixes; check Prisma Access status portal.
Detection. GlobalProtect connection logs: look for authentication events with auth_method: cookie from IP addresses not previously associated with the authenticated username or the organisation's VPN-client pool. Cookie-based auth events from brand-new source IPs without a preceding web-based MFA event warrant immediate investigation. PAN-OS system logs: globalprotectgateway-config-succ events authenticated via cookie from non-enrolled endpoints (no prior SCEP or Panorama device-cert association). Network: VPN sessions with a deliberately spoofed MAC address pattern reused across geographically-disparate source IPs (trivially detectable from GlobalProtect connection metadata) are a strong indicator of this attack pattern; MAC-based anomaly detection in the VPN segment should alert. SIEM correlation: chain cookie-auth events to downstream firewall allow policies allowing that VPN IP to reach sensitive segments, and alert when a new-IP cookie-auth session moves east-west within minutes.
Hardening / mitigation. Immediate: upgrade PAN-OS to the fixed versions per the vendor advisory. If patching cannot be completed within 24 hours: (a) disable authentication override cookies entirely in the GlobalProtect gateway and portal settings (Authentication > No Cookie Required on Pre-Logon Connections); this forces per-session MFA but removes the attack surface. (b) If auth-override cookies are required: generate a dedicated certificate for GlobalProtect used exclusively for that service and not shared with the HTTPS management or any other feature. This removes the public-key extraction path. Verify via show system info and show sslmgr-store that the GlobalProtect GP cert and the HTTPS service cert are distinct objects. Prisma Access organisations: apply any available Prisma Access emergency fix and validate the Prisma Access security advisory for tenant-specific remediation steps.