CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Palo Alto Networks Prisma Access

product · product:palo-alto-networks-prisma-access

Coverage
1
first 2026-05-30 → last 2026-10-06
Latest activity
2026-10-06
CISA marks the exploited GlobalProtect VPN bypass as used in ransomware; Arctic Wolf traced Qilin intrusions…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, finance, healthcare · regions: europe
Sources cited
7
6 hosts

Action items (2)

Do-now tasks recorded on the entries about Palo Alto Networks Prisma Access, newest first. Check the date before acting on an older one.

  • Patch every PAN-OS GlobalProtect portal and gateway to the fixed release in Palo Alto's advisory for its train, or disable authentication override cookies or give them a certificate that no other service uses, then force one re-authentication so override cookies regenerate.
    2026-05-30CVE-2026-0257
  • On every GlobalProtect gateway that was internet-reachable and unpatched at any time since 2026-05-17, treat the network behind it as a ransomware compromise-assessment target: review VPN sessions that authenticated by cookie from unexpected sources, then check Windows hosts for the artifacts Arctic Wolf describes (a ransomware payload staged under C:\\PerfLogs, a PsExec service, an LSASS dump written through comsvcs.dll to an .odt file, an ntdsutil media copy of the Active Directory database, and cleared event logs).
    2026-05-30CVE-2026-0257

Defender insights

What each entry about Palo Alto Networks Prisma Access tells a defender to do, newest first.

2026-05-30HIGHexploitedCISA marks the exploited GlobalProtect VPN bypass as used in ransomware; Arctic Wolf traced Qilin intrusions to it

Exposure · detection

Story timeline

  1. 2026-05-30CVE-2026-0257, Palo Alto PAN-OS GlobalProtect: pre-auth authentication bypass via certificate reuse, marked by CISA as used in ransomware campaigns
    trending-vulnerabilitiesCISA marks the exploited GlobalProtect VPN bypass as used in ransomware; Arctic Wolf traced Qilin intrusions to it

Hunting pivots

CVEs (exploited first)
Releases covered
Palo Alto Networks Prisma Access
ATT&CK techniques (15 across 10 tactics)

15 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessExternal Remote Services · Exploit Public-Facing Application
  • ExecutionScheduled Task/Job: Scheduled Task · System Services: Service Execution
  • PersistenceScheduled Task/Job: Scheduled Task · External Remote Services · Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
  • Privilege EscalationScheduled Task/Job: Scheduled Task · Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
  • Defense ImpairmentDisable or Modify Tools · Disable or Modify Tools: Clear Windows Event Logs
  • Credential AccessOS Credential Dumping: LSASS Memory · OS Credential Dumping: NTDS
  • Lateral MovementRemote Services: Remote Desktop Protocol · Remote Services: SMB/Windows Admin Shares
  • Command and ControlRemote Access Tools
  • ExfiltrationExfiltration Over Web Service: Exfiltration to Cloud Storage
  • ImpactData Encrypted for Impact · Inhibit System Recovery

Initial Access TA0001

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗

Execution TA0002

T1053.005Scheduled Task/Job: Scheduled Task×1

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗

T1569.002System Services: Service Execution×1

Adversaries may abuse the Windows service control manager to execute malicious commands or payloads. The Windows service control manager (<code>services.exe</code>) is an interface to manage and manipulate services. The service control manager is accessible to users via GUI components as well as system utilities such as <code>sc.exe</code> and Net.

Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗

Persistence TA0003

T1053.005Scheduled Task/Job: Scheduled Task×1

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗

T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.

Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗

Privilege Escalation TA0004

T1053.005Scheduled Task/Job: Scheduled Task×1

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗

T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.

Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗

Defense Impairment TA0112

T1685Disable or Modify Tools×1

Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.

Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗

T1685.005Disable or Modify Tools: Clear Windows Event Logs×1

Adversaries may clear Windows Event Logs to hide the activity of an intrusion. Windows Event Logs are a record of a computer's alerts and notifications. There are three system-defined sources of events: System, Application, and Security, with five event types: Error, Warning, Information, Success Audit, and Failure Audit.

Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗

Credential Access TA0006

T1003.001OS Credential Dumping: LSASS Memory×1

Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). After a user logs on, the system generates and stores a variety of credential materials in LSASS process memory. These credential materials can be harvested by an administrative user or SYSTEM and used to conduct Lateral Movement using Use Alternate Authentication Material.

Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗

T1003.003OS Credential Dumping: NTDS×1

Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights. By default, the NTDS file (NTDS.dit) is located in <code>%SystemRoot%\NTDS\Ntds.dit</code> of a domain controller.

Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗

Lateral Movement TA0008

T1021.001Remote Services: Remote Desktop Protocol×1

Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.

Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗

T1021.002Remote Services: SMB/Windows Admin Shares×1

Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB). The adversary may then perform actions as the logged-on user.

Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗

Command and Control TA0011

T1219Remote Access Tools×1

An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.

Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗

Exfiltration TA0010

T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage×1

Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.

Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗

Impact TA0040

T1486Data Encrypted for Impact×1

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗

T1490Inhibit System Recovery×1

Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery. This may deny access to available backups and recovery options.

Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗

Entries about Palo Alto Networks Prisma Access (1)

2026-05-30 · view entry permalink →

HIGHCVE-2026-0257exploitedupdatedNATOA1

CVE-2026-0257, Palo Alto PAN-OS GlobalProtect: pre-auth authentication bypass via certificate reuse, marked by CISA as used in ransomware campaigns

Authentication override cookies in PAN-OS GlobalProtect let a portal or gateway issue a cookie that a user presents in place of re-authenticating, and the feature is not enabled by default (Rapid7, 2026-05-29). Palo Alto Networks says the flaw affects firewalls with a GlobalProtect portal or gateway where authentication override cookies are enabled and a specific certificate configuration exists, classes it as CWE-565 (reliance on cookies without validation and integrity checking), and scores it CVSS 4.0 7.8 with exploit maturity Attacked (Palo Alto Networks PSIRT, 2026-05-13). Rapid7's analysis is that when the certificate used for the cookies is reused for another feature such as the HTTPS service of the portal or gateway, a remote unauthenticated attacker can discover that certificate's public key, forge an arbitrary cookie that the server decrypts and trusts, and bypass authentication; Rapid7 Labs published a proof-of-concept script that tests for it (Rapid7, 2026-05-29). Palo Alto Networks says it is aware of limited exploit attempts on unpatched devices without mitigations applied (Palo Alto Networks PSIRT, 2026-05-13); Rapid7 MDR dates the earliest observed exploitation to 17 May 2026 and saw two waves, on 18 May from Vultr-hosted infrastructure and on 21 May from Dromatics Systems, which it believes are likely the same threat actor because of a consistent MAC address (Rapid7, 2026-05-29). CISA's KEV catalog lists the CVE with a date added of 29 May 2026 (CISA KEV catalog, 2026-10-04).

Affected are PAN-OS 12.1, 11.2, 11.1 and 10.2 releases below the fixed builds in Palo Alto's table and Prisma Access 11.2 and 10.2; Panorama and Cloud NGFW are not affected (Palo Alto Networks PSIRT, 2026-05-13). The solution table names the first fixed build for each minor release, for example 12.1.4-h6 or 12.1.7 and later for 12.1.2 through 12.1.4, 11.2.12 or later for 11.2.11, 11.1.15 or later for 11.1.14, and 10.2.18-h6 or later on the 10.2 train, while Prisma Access 11.2 needs 11.2.7-h13 or later and 10.2 needs 10.2.10-h36 or later (Palo Alto Networks PSIRT, 2026-05-13). After the upgrade users must re-authenticate once, because the firewall regenerates the cookie with a more secure method (Palo Alto Networks PSIRT, 2026-05-13). Palo Alto's mitigations are a dedicated certificate used only for authentication override cookies, or disabling Authentication Override (Palo Alto Networks PSIRT, 2026-05-13).

Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied.

Palo Alto Networks PSIRT

Due to the consistent MAC address, Rapid7 believes both waves of exploitation are likely from the same threat actor (TA).

Rapid7

Arctic Wolf investigated multiple distinct intrusions during June 2026 that resulted in Qilin ransomware deployment, all originating from exploitation of CVE-2026-0257 against Palo Alto Networks firewall appliances.

Arctic Wolf Labs 2026-07-20
Updaterun 2026-06-10-c84347b2actionsevidencesectorssourcesbody

Unit 42's 9 June update on CVE-2026-0257 confirms that a limited number of probed PAN-OS GlobalProtect devices had attacker-established, gateway-connected VPN sessions, moving this from "exploit attempts observed" to confirmed successful exploitation (Unit 42, 2026-06-09). The bug (CWE-565, reliance on a cookie without integrity checking) lets an attacker extract the encryption certificate's public key from the TLS handshake and forge authentication-override cookies when that certificate is shared with another function; Rapid7 dates successful exploitation to 17 May from low-cost hosting IPs (Rapid7, 2026-05-29).

Affected: PAN-OS 10.2/11.1/11.2/12.1 and Prisma Access where authentication override is enabled with a shared certificate; patched in 12.1.7+, 11.2.12+, 11.1.15+, 10.2.18-h6+ and corresponding Prisma builds (Palo Alto Networks, 2026-06-03). Patch, then force one re-authentication so override cookies regenerate; as a workaround disable authentication override or assign it a dedicated certificate. Hunt GlobalProtect gateway logs for auth-method=cookie from unexpected source IPs.

Updaterun 2026-06-17-e102009cevidenceregionssectorssourcesbody

Palo Alto's Unit 42 confirms an active exploitation campaign against the GlobalProtect cookie authentication-bypass (CVE-2026-0257) (Unit 42, 2026-06-09). The flaw (CWE-565, reliance on cookies without validation and integrity checking) lets an attacker forge a session and establish a VPN tunnel without credentials when the override feature is enabled (Palo Alto Networks PSIRT).

Arctic Wolf's telemetry documents post-exploitation consistent with Impacket tooling (SMB lateral movement, anonymous NTLM logon, share enumeration and domain-user discovery) across insurance, finance, manufacturing, education, engineering and healthcare targets in North America and Europe (Arctic Wolf, 2026-06-11). NCSC-CH refreshed its Security Hub advisory on 2026-06-16 to flag the Unit 42 confirmation (NCSC-CH Security Hub, 2026-06-16). Defenders: disable "Authentication Override" if not required, patch to fixed PAN-OS builds, and audit sessions since 17 May for Impacket-pattern lateral movement (EID 4624 Type 3 from unexpected IPs, SMB enumeration EID 5140/5145).

Updaterun 2026-10-06T0405Z-inteltitleheadlinesummarypriorityimmediate_actiontagsentitiestechniquesaffected_productssourcesevidencesourcing_noteclassificationactionsbody

CISA's Known Exploited Vulnerabilities catalog (version 2026.10.04) now marks CVE-2026-0257 as used in known ransomware campaigns; the record names no group and its date of addition remains 2026-05-29 (CISA KEV catalog, 2026-10-04). Arctic Wolf Labs' report of 2026-07-20 says it investigated multiple distinct intrusions in June 2026 that ended in Qilin ransomware deployment, all originating from exploitation of CVE-2026-0257 against Palo Alto Networks firewalls, and that the post-exploitation tradecraft ranged from rapid encryption-only operations to double extortion, possibly suggesting several affiliates of the Qilin ransomware-as-a-service operation (Arctic Wolf, 2026-07-20).

The chain Arctic Wolf describes starts with a GlobalProtect VPN session obtained through the cookie bypass, in some cases from systems that identified themselves as kali, and continues with registry Run-key persistence that points at a ransomware payload staged under C:\PerfLogs, remote-access tools (AnyDesk, Ngrok, LogMeIn and, in one case, a scheduled task consistent with MeshAgent), LSASS credential theft through rundll32 and comsvcs.dll into a file with an .odt extension, a full copy of the Active Directory database with ntdsutil, lateral movement with PsExec over administrative shares and RDP, a PowerShell routine that clears every Windows event log with records, and Microsoft Defender real-time protection disabled in some cases (Arctic Wolf, 2026-07-20). In the double-extortion cases data went to the MEGA cloud storage service with Rclone before encryption, and the attackers targeted the Veeam backup infrastructure before deploying the ransomware; some intrusions involved no data theft before encryption (Arctic Wolf, 2026-07-20). A gateway that was reachable and unpatched therefore needs a compromise assessment of the Windows estate behind it, not only the patch and a forced re-authentication.

vulnerability30 May 05:00Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Vulns1

Source distribution

  • arcticwolf.com2 (29%)
  • cisa.gov1 (14%)
  • rapid7.com1 (14%)
  • security-hub.ncsc.admin.ch1 (14%)
  • security.paloaltonetworks.com1 (14%)
  • unit42.paloaltonetworks.com1 (14%)