CVE-2026-0257, Palo Alto PAN-OS GlobalProtect: Pre-Auth Authentication Bypass via Certificate Reuse
Defender actions
- Patch PAN-OS to fixed versions or disable GlobalProtect auth-override cookies today; CVE-2026-0257 is a pre-auth VPN bypass with confirmed in-the-wild exploitation waves and a public PoC; CISA KEV deadline is 1 June 2026 for FCEB agencies. EU/Swiss public-sector perimeter VPN defenders should treat this as emergency-change priority. References: Palo Alto PSIRT, Rapid7 ETR.
- Force re-authentication on patched PAN-OS GlobalProtect gateways (CVE-2026-0257) so authentication-override cookies regenerate, and run a forensic lookback from 17 May for cookie-auth sessions from unexpected IPs; exploitation is now confirmed successful, not just attempted.
Analysis
Authentication override cookies in PAN-OS GlobalProtect are encrypted using the portal or gateway certificate. When that same certificate is shared with another service (most commonly the HTTPS service, a non-default but operationally common configuration), an unauthenticated attacker can extract the certificate's public key from the HTTPS service and forge valid authentication override cookies, obtaining a full VPN session without credentials (Palo Alto Networks PSIRT, 2026-05-29). Root cause: CWE-565 (Reliance on Cookies Without Validation and Integrity Checking). CVSS 4.0 = 7.8 HIGH (Exploit Maturity: ATTACKED). Affected: PAN-OS 10.2.x, 11.1.x, 11.2.x, 12.1.x; Prisma Access 10.2 and 11.2; Panorama and Cloud NGFW are not affected. Rapid7 MDR observed two exploitation waves (18 May from Vultr-hosted infrastructure, 21 May from Dromatics Systems IP space) both sharing a deliberately spoofed, easily-recognisable MAC address pattern and machine names GP-CLIENT (Linux) and DESKTOP-GP01 (Windows), indicating a single actor (Rapid7 ETR, 2026-05-29). A public PoC is available. CISA added CVE-2026-0257 to KEV on 29 May. Detection: GlobalProtect connection logs with cookie-based auth-override events sourced from unexpected IP blocks; sessions authenticating without prior MFA web-step; PCAP anomaly of identical MAC across geographically-disparate sessions. Immediate remediation: upgrade to fixed PAN-OS versions (10.2.7-h34+, 11.1.4-h33+, 11.2.4-h17+, 12.1.4-h6+ and subsequent maintenance releases, full version table in the vendor advisory); or disable authentication override cookies; or assign an exclusive certificate to GlobalProtect not shared with any other service.
Cited evidence
Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied.
Rapid7 MDR observed a second wave of exploitation on May 21st, and due to consistent MAC address, they believe both waves of exploitation are likely from the same threat actor.
UPDATE (originally covered 2026-05-30): Unit 42's 9 June update on CVE-2026-0257 confirms that a limited number of probed PAN-OS GlobalProtect devices had attacker-established, gateway-connected VPN sessions, moving this from "exploit attempts observed" to confirmed successful exploitation (Unit …
UPDATE (originally covered 2026-05-30): Palo Alto's Unit 42 confirms an active exploitation campaign against the GlobalProtect cookie authentication-bypass (CVE-2026-0257) running since approximately late May (Unit 42, 2026-06-09).
Updates2
Unit 42's 9 June update on CVE-2026-0257 confirms that a limited number of probed PAN-OS GlobalProtect devices had attacker-established, gateway-connected VPN sessions, moving this from "exploit attempts observed" to confirmed successful exploitation (Unit 42, 2026-06-09). The bug (CWE-565, reliance on a cookie without integrity checking) lets an attacker extract the encryption certificate's public key from the TLS handshake and forge authentication-override cookies when that certificate is shared with another function; Rapid7 dates successful exploitation to 17 May from low-cost hosting IPs (Rapid7, 2026-05-29).
Affected: PAN-OS 10.2/11.1/11.2/12.1 and Prisma Access where authentication override is enabled with a shared certificate; patched in 12.1.7+, 11.2.12+, 11.1.15+, 10.2.18-h6+ and corresponding Prisma builds (Palo Alto Networks, 2026-06-03). Patch, then force one re-authentication so override cookies regenerate; as a workaround disable authentication override or assign it a dedicated certificate. Hunt GlobalProtect gateway logs for auth-method=cookie from unexpected source IPs.
Palo Alto's Unit 42 confirms an active exploitation campaign against the GlobalProtect cookie authentication-bypass (CVE-2026-0257) running since approximately late May (Unit 42, 2026-06-09). The flaw (CWE-565) decrypts an authentication-override cookie without any signature verification, letting an attacker forge a session and establish a VPN tunnel without credentials when the override feature is enabled (Palo Alto Networks PSIRT).
Arctic Wolf's telemetry documents post-exploitation consistent with Impacket tooling (SMB lateral movement, anonymous NTLM logon, share enumeration and domain-user discovery) across insurance, finance, manufacturing, education, engineering and healthcare targets in North America and Europe (Arctic Wolf, 2026-06-11). NCSC-CH refreshed its Security Hub advisory on 2026-06-16 to flag the Unit 42 confirmation (NCSC-CH Security Hub, 2026-06-16). Defenders: disable "Authentication Override" if not required, patch to fixed PAN-OS builds, and audit sessions since late May for Impacket-pattern lateral movement (EID 4624 Type 3 from unexpected IPs, SMB enumeration EID 5140/5145).
Sources5
Revision history
- Published 2026-05-30-aca445cc
- Update 2026-06-10-c84347b2
UPDATE (originally covered 2026-05-30): Unit 42's 9 June update on CVE-2026-0257 confirms that a limited number of probed PAN-OS GlobalProtect devices had attacker-established, gateway-connected VPN sessions, moving this from "exploit attempts observed" to confirmed successful exploitation (Unit 42, 2026-06-09).
Changed: actions evidence sectors sources body
- Update 2026-06-17-e102009c
PAN-OS GlobalProtect CVE-2026-0257 exploitation wave hits European targets, Arctic Wolf documents Impacket-style SMB lateral movement post-auth-bypass; NCSC-CH refreshed its advisory on 2026-06-16 (§ 4).
Changed: evidence regions sectors sources body
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.