---
schema: 1
kind: vulnerability
title: >
  CVE-2026-0257 — Palo Alto PAN-OS GlobalProtect: Pre-Auth Authentication Bypass via Certificate
  Reuse
headline: >
  CVE-2026-0257 — Palo Alto PAN-OS GlobalProtect: Pre-Auth Authentication Bypass via Certificate
  Reuse
summary: >
  CVE-2026-0257 — PAN-OS GlobalProtect pre-auth VPN authentication bypass, CISA KEV, confirmed
  in-the-wild exploitation (Palo Alto PSIRT, 2026-05-29). An attacker forges valid auth-override
  cookies by re-using the GlobalProtect certificate from the colocated HTTPS service; no
  credentials required. Rapid7 observed two exploitation waves. Patch immediately or disable
  auth-override cookies.
discovered_at: "2026-05-30T05:00:04Z"
updated_at: "2026-06-17T05:14:33Z"
event_date: 2026-05-29
run_id: 2026-05-30-aca445cc
priority: critical
immediate_action:
  title: "Patch PAN-OS GlobalProtect now: pre-auth VPN bypass confirmed exploited in the wild"
  action: >
    Palo Alto Networks confirmed active exploitation of CVE-2026-0257, a pre-auth authentication
    bypass in GlobalProtect portal and gateway enabled when authentication override cookies share a
    certificate with the HTTPS service. An unauthenticated attacker can forge a valid auth cookie
    and establish a GlobalProtect VPN session. Rapid7 MDR observed two exploitation waves (18 and 21
    May) from consistent actor infrastructure; a public PoC is available at
    github.com/sfewer-r7/CVE-2026-0257.
tags:
  - vulnerabilities
  - actively-exploited
  - pre-auth
  - auth-bypass
  - cisa-kev
  - patch-available
regions:
  - global
  - europe
sectors:
  - public-sector
  - finance
  - healthcare
  - education
entities: []
techniques: []
affected_products: []
cves:
  - id: CVE-2026-0257
    cvss: "7.8"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - cisa-kev
      - patch-available
sources:
  - url: "https://security.paloaltonetworks.com/CVE-2026-0257"
    publisher: Palo Alto Networks PSIRT
    role: primary
  - url: "https://www.rapid7.com/blog/post/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257/"
    publisher: Rapid7 ETR
    role: corroborating
  - url: "https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/"
    publisher: "Unit 42, 2026-06-09"
    role: corroborating
  - url: "https://arcticwolf.com/resources/blog/arctic-wolf-observes-increase-in-palo-alto-networks-globalprotect-authentication-bypass-exploitation-via-cve-2026-0257/"
    publisher: "Arctic Wolf, 2026-06-11"
    role: corroborating
  - url: "https://security-hub.ncsc.admin.ch/#/posts/12605"
    publisher: "NCSC-CH Security Hub, 2026-06-16"
    role: corroborating
closed_sources: []
evidence:
  - quote: Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied.
    publisher: Palo Alto Networks PSIRT
  - quote: "Rapid7 MDR observed a second wave of exploitation on May 21st, and due to consistent MAC address, they believe both waves of exploitation are likely from the same threat actor."
    publisher: Rapid7
  - quote: "UPDATE (originally covered 2026-05-30): Unit 42's 9 June update on CVE-2026-0257 confirms that a limited number of probed PAN-OS GlobalProtect devices had attacker-established, gateway-connected VPN sessions, moving this from \"exploit attempts observed\" to confirmed successful exploitation (Unit …"
    publisher: ctipilot v2 brief (migrated)
  - quote: "UPDATE (originally covered 2026-05-30): Palo Alto's Unit 42 confirms an active exploitation campaign against the GlobalProtect cookie authentication-bypass (CVE-2026-0257) running since approximately late May (Unit 42, 2026-06-09)."
    publisher: ctipilot v2 brief (migrated)
verification: multi-source
sourcing_note: null
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification: null
watchlist_hit: false
actions:
  - "**Patch PAN-OS to fixed versions or disable GlobalProtect auth-override cookies today** — CVE-2026-0257 is a pre-auth VPN bypass with confirmed in-the-wild exploitation waves and a public PoC; CISA KEV deadline is 1 June 2026 for FCEB agencies. EU/Swiss public-sector perimeter VPN defenders should treat this as emergency-change priority. References: [Palo Alto PSIRT](https://security.paloaltonetworks.com/CVE-2026-0257), [Rapid7 ETR](https://www.rapid7.com/blog/post/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257/)."
  - "**Force re-authentication on patched PAN-OS GlobalProtect gateways (CVE-2026-0257)** so authentication-override cookies regenerate, and run a forensic lookback from 17 May for cookie-auth sessions from unexpected IPs — exploitation is now confirmed successful, not just attempted."
updates:
  - at: "2026-06-10T05:00:16Z"
    run_id: 2026-06-10-c84347b2
    type: update
    summary: >
      UPDATE (originally covered 2026-05-30): Unit 42's 9 June update on CVE-2026-0257 confirms that a
      limited number of probed PAN-OS GlobalProtect devices had attacker-established,
      gateway-connected VPN sessions, moving this from "exploit attempts observed" to confirmed
      successful exploitation (Unit 42, 2026-06-09).
    fields:
      - actions
      - evidence
      - sectors
      - sources
      - body
    merged_from: 2026-06-10/pan-os-globalprotect-auth-bypass-cve-2026-0257-unit-42-confi
  - at: "2026-06-17T05:14:33Z"
    run_id: 2026-06-17-e102009c
    type: update
    summary: >
      PAN-OS GlobalProtect CVE-2026-0257 exploitation wave hits European targets — Arctic Wolf
      documents Impacket-style SMB lateral movement post-auth-bypass; NCSC-CH refreshed its advisory
      on 2026-06-16 (§ 4).
    fields:
      - evidence
      - regions
      - sectors
      - sources
      - body
    merged_from: 2026-06-17/pan-os-globalprotect-cve-2026-0257-exploitation-wave-with-im
migrated_from: briefs/2026-05-30.md
---

Authentication override cookies in PAN-OS GlobalProtect are encrypted using the portal or gateway certificate. When that same certificate is shared with another service (most commonly the HTTPS service — a non-default but operationally common configuration), an unauthenticated attacker can extract the certificate's public key from the HTTPS service and forge valid authentication override cookies, obtaining a full VPN session without credentials ([Palo Alto Networks PSIRT, 2026-05-29](https://security.paloaltonetworks.com/CVE-2026-0257)). Root cause: CWE-565 (Reliance on Cookies Without Validation and Integrity Checking). CVSS 4.0 = 7.8 HIGH (Exploit Maturity: ATTACKED). Affected: PAN-OS 10.2.x, 11.1.x, 11.2.x, 12.1.x; Prisma Access 10.2 and 11.2; Panorama and Cloud NGFW are not affected. Rapid7 MDR observed two exploitation waves — 18 May from Vultr-hosted infrastructure, 21 May from Dromatics Systems IP space — both sharing a deliberately spoofed, easily-recognisable MAC address pattern and machine names GP-CLIENT (Linux) and DESKTOP-GP01 (Windows), indicating a single actor ([Rapid7 ETR, 2026-05-29](https://www.rapid7.com/blog/post/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257/)). A public PoC is available. CISA added CVE-2026-0257 to KEV on 29 May. Detection: GlobalProtect connection logs with cookie-based auth-override events sourced from unexpected IP blocks; sessions authenticating without prior MFA web-step; PCAP anomaly of identical MAC across geographically-disparate sessions. Immediate remediation: upgrade to fixed PAN-OS versions (10.2.7-h34+, 11.1.4-h33+, 11.2.4-h17+, 12.1.4-h6+ and subsequent maintenance releases — full version table in the vendor advisory); or disable authentication override cookies; or assign an exclusive certificate to GlobalProtect not shared with any other service.

## Update — 2026-06-10T05:00:16Z

Unit 42's 9 June update on CVE-2026-0257 confirms that a limited number of probed PAN-OS GlobalProtect devices had attacker-established, gateway-connected VPN sessions, moving this from "exploit attempts observed" to confirmed successful exploitation ([Unit 42, 2026-06-09](https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/)). The bug (CWE-565, reliance on a cookie without integrity checking) lets an attacker extract the encryption certificate's public key from the TLS handshake and forge authentication-override cookies when that certificate is shared with another function; Rapid7 dates successful exploitation to 17 May from low-cost hosting IPs ([Rapid7, 2026-05-29](https://www.rapid7.com/blog/post/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257/)).

Affected: PAN-OS 10.2/11.1/11.2/12.1 and Prisma Access where authentication override is enabled with a shared certificate; patched in 12.1.7+, 11.2.12+, 11.1.15+, 10.2.18-h6+ and corresponding Prisma builds ([Palo Alto Networks, 2026-06-03](https://security.paloaltonetworks.com/CVE-2026-0257)). Patch, then force one re-authentication so override cookies regenerate; as a workaround disable authentication override or assign it a dedicated certificate. Hunt GlobalProtect gateway logs for `auth-method=cookie` from unexpected source IPs.

## Update — 2026-06-17T05:14:33Z

Palo Alto's Unit 42 confirms an active exploitation campaign against the GlobalProtect cookie authentication-bypass (CVE-2026-0257) running since approximately late May ([Unit 42, 2026-06-09](https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/)). The flaw (CWE-565) decrypts an authentication-override cookie without any signature verification, letting an attacker forge a session and establish a VPN tunnel without credentials when the override feature is enabled ([Palo Alto Networks PSIRT](https://security.paloaltonetworks.com/CVE-2026-0257)).

Arctic Wolf's telemetry documents post-exploitation consistent with Impacket tooling — SMB lateral movement, anonymous NTLM logon, share enumeration and domain-user discovery — across insurance, finance, manufacturing, education, engineering and healthcare targets in North America and Europe ([Arctic Wolf, 2026-06-11](https://arcticwolf.com/resources/blog/arctic-wolf-observes-increase-in-palo-alto-networks-globalprotect-authentication-bypass-exploitation-via-cve-2026-0257/)). NCSC-CH refreshed its Security Hub advisory on 2026-06-16 to flag the Unit 42 confirmation ([NCSC-CH Security Hub, 2026-06-16](https://security-hub.ncsc.admin.ch/#/posts/12605)). Defenders: disable "Authentication Override" if not required, patch to fixed PAN-OS builds, and audit sessions since late May for Impacket-pattern lateral movement (EID 4624 Type 3 from unexpected IPs, SMB enumeration EID 5140/5145).
