The active exploitation of Palo Alto Networks GlobalProtect CVE-2026-0257 is a serious reminder that VPN gateways remain one of the most attractive entry points into corporate networks. The flaw allows attackers to bypass authentication and establish unauthorized VPN connections on vulnerable PAN-OS devices when specific GlobalProtect authentication override cookie configurations are in use.
This is especially dangerous because VPN access is not just a login event. It can become direct network access. Rapid7 observed exploitation across multiple customers starting around May 17, 2026, with attackers using forged authentication override cookies targeting the local administrator account. In some cases, attackers were able to connect via VPN using forged cookies, which is exactly the kind of “trusted access” nobody wants to discover in hindsight.
The root issue is that GlobalProtect trusted decrypted authentication override cookie contents without proper signature verification. If the same certificate was reused for HTTPS services and authentication override cookies, attackers could retrieve the public certificate and generate forged cookies accepted by the device. Because apparently certificate reuse has once again found a way to make everyone’s week worse.
Organizations using GlobalProtect should immediately apply the latest PAN-OS security updates, disable authentication override if not required, and ensure the authentication override feature uses a separate certificate that is not shared with other services. Security teams should also review VPN logs for suspicious authentication patterns, unexpected local administrator access, unusual source infrastructure, and unauthorized VPN sessions.
The broader lesson is simple: remote access infrastructure must be patched, hardened, and continuously monitored. VPN appliances sit at the edge of the enterprise and often lead directly into internal networks. A misconfigured or unpatched VPN is not just a vulnerable device. It is a potential front door with better branding.
Palo Alto Networks is warning that hackers are now exploiting a PAN-OS GlobalProtect authentication bypass flaw, tracked as CVE-2026-0257, in attacks attempting to breach corporate networks. [...]
Source: Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks via Bleeping Computer — published 30 May 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.