CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to Daily brief 2026-05-30
CRITICALCVE-2026-0257exploitedupdatedvulnerability

CVE-2026-0257, Palo Alto PAN-OS GlobalProtect: Pre-Auth Authentication Bypass via Certificate Reuse

Defender actions

  • Patch PAN-OS to fixed versions or disable GlobalProtect auth-override cookies today; CVE-2026-0257 is a pre-auth VPN bypass with confirmed in-the-wild exploitation waves and a public PoC; CISA KEV deadline is 1 June 2026 for FCEB agencies. EU/Swiss public-sector perimeter VPN defenders should treat this as emergency-change priority. References: Palo Alto PSIRT, Rapid7 ETR.
  • Force re-authentication on patched PAN-OS GlobalProtect gateways (CVE-2026-0257) so authentication-override cookies regenerate, and run a forensic lookback from 17 May for cookie-auth sessions from unexpected IPs; exploitation is now confirmed successful, not just attempted.

Analysis

Authentication override cookies in PAN-OS GlobalProtect are encrypted using the portal or gateway certificate. When that same certificate is shared with another service (most commonly the HTTPS service, a non-default but operationally common configuration), an unauthenticated attacker can extract the certificate's public key from the HTTPS service and forge valid authentication override cookies, obtaining a full VPN session without credentials (Palo Alto Networks PSIRT, 2026-05-29). Root cause: CWE-565 (Reliance on Cookies Without Validation and Integrity Checking). CVSS 4.0 = 7.8 HIGH (Exploit Maturity: ATTACKED). Affected: PAN-OS 10.2.x, 11.1.x, 11.2.x, 12.1.x; Prisma Access 10.2 and 11.2; Panorama and Cloud NGFW are not affected. Rapid7 MDR observed two exploitation waves (18 May from Vultr-hosted infrastructure, 21 May from Dromatics Systems IP space) both sharing a deliberately spoofed, easily-recognisable MAC address pattern and machine names GP-CLIENT (Linux) and DESKTOP-GP01 (Windows), indicating a single actor (Rapid7 ETR, 2026-05-29). A public PoC is available. CISA added CVE-2026-0257 to KEV on 29 May. Detection: GlobalProtect connection logs with cookie-based auth-override events sourced from unexpected IP blocks; sessions authenticating without prior MFA web-step; PCAP anomaly of identical MAC across geographically-disparate sessions. Immediate remediation: upgrade to fixed PAN-OS versions (10.2.7-h34+, 11.1.4-h33+, 11.2.4-h17+, 12.1.4-h6+ and subsequent maintenance releases, full version table in the vendor advisory); or disable authentication override cookies; or assign an exclusive certificate to GlobalProtect not shared with any other service.

Cited evidence

Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied.

Palo Alto Networks PSIRT

Rapid7 MDR observed a second wave of exploitation on May 21st, and due to consistent MAC address, they believe both waves of exploitation are likely from the same threat actor.

Rapid7

UPDATE (originally covered 2026-05-30): Unit 42's 9 June update on CVE-2026-0257 confirms that a limited number of probed PAN-OS GlobalProtect devices had attacker-established, gateway-connected VPN sessions, moving this from "exploit attempts observed" to confirmed successful exploitation (Unit …

UPDATE (originally covered 2026-05-30): Palo Alto's Unit 42 confirms an active exploitation campaign against the GlobalProtect cookie authentication-bypass (CVE-2026-0257) running since approximately late May (Unit 42, 2026-06-09).

ctipilot v2 brief (migrated)

Updates2

Update

Unit 42's 9 June update on CVE-2026-0257 confirms that a limited number of probed PAN-OS GlobalProtect devices had attacker-established, gateway-connected VPN sessions, moving this from "exploit attempts observed" to confirmed successful exploitation (Unit 42, 2026-06-09). The bug (CWE-565, reliance on a cookie without integrity checking) lets an attacker extract the encryption certificate's public key from the TLS handshake and forge authentication-override cookies when that certificate is shared with another function; Rapid7 dates successful exploitation to 17 May from low-cost hosting IPs (Rapid7, 2026-05-29).

Affected: PAN-OS 10.2/11.1/11.2/12.1 and Prisma Access where authentication override is enabled with a shared certificate; patched in 12.1.7+, 11.2.12+, 11.1.15+, 10.2.18-h6+ and corresponding Prisma builds (Palo Alto Networks, 2026-06-03). Patch, then force one re-authentication so override cookies regenerate; as a workaround disable authentication override or assign it a dedicated certificate. Hunt GlobalProtect gateway logs for auth-method=cookie from unexpected source IPs.

Update

Palo Alto's Unit 42 confirms an active exploitation campaign against the GlobalProtect cookie authentication-bypass (CVE-2026-0257) running since approximately late May (Unit 42, 2026-06-09). The flaw (CWE-565) decrypts an authentication-override cookie without any signature verification, letting an attacker forge a session and establish a VPN tunnel without credentials when the override feature is enabled (Palo Alto Networks PSIRT).

Arctic Wolf's telemetry documents post-exploitation consistent with Impacket tooling (SMB lateral movement, anonymous NTLM logon, share enumeration and domain-user discovery) across insurance, finance, manufacturing, education, engineering and healthcare targets in North America and Europe (Arctic Wolf, 2026-06-11). NCSC-CH refreshed its Security Hub advisory on 2026-06-16 to flag the Unit 42 confirmation (NCSC-CH Security Hub, 2026-06-16). Defenders: disable "Authentication Override" if not required, patch to fixed PAN-OS builds, and audit sessions since late May for Impacket-pattern lateral movement (EID 4624 Type 3 from unexpected IPs, SMB enumeration EID 5140/5145).

Sources5

Revision history

  1. Published 2026-05-30-aca445cc
  2. Update 2026-06-10-c84347b2

    UPDATE (originally covered 2026-05-30): Unit 42's 9 June update on CVE-2026-0257 confirms that a limited number of probed PAN-OS GlobalProtect devices had attacker-established, gateway-connected VPN sessions, moving this from "exploit attempts observed" to confirmed successful exploitation (Unit 42, 2026-06-09).

    Changed: actions evidence sectors sources body

  3. Update 2026-06-17-e102009c

    PAN-OS GlobalProtect CVE-2026-0257 exploitation wave hits European targets, Arctic Wolf documents Impacket-style SMB lateral movement post-auth-bypass; NCSC-CH refreshed its advisory on 2026-06-16 (§ 4).

    Changed: evidence regions sectors sources body

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.