Palo Alto Networks disclosed CVE-2026-0257, an authentication bypass flaw in PAN-OS GlobalProtect portal and gateway that can allow attackers to establish unauthorized VPN sessions by forging authentication override cookies. The issue occurs when PAN-OS trusts decrypted GlobalProtect cookies without validating a signature, particularly when the same certificate is used for both HTTPS and authentication override functions. Affected products include specified PAN-OS and Prisma Access versions, while Cloud NGFW and Panorama were reported as not impacted; Palo Alto Networks also published fixed releases and mitigations such as using a dedicated certificate for authentication override cookies or disabling authentication override.
Palo Alto Networks reported limited exploitation attempts against unpatched devices, and subsequent reporting said attacks were observed in the wild against multiple organizations, with activity beginning in mid-May and using infrastructure linked to Vultr and Dromatics Systems. CISA added CVE-2026-0257 to its Known Exploited Vulnerabilities catalog, and regional defenders warned that successful compromise could give intruders direct access to corporate VPNs, creating a path for lateral movement, credential theft, and exposure of sensitive internal environments, including OT/SCADA networks. A separate Palo Alto advisory released alongside it also addressed CVE-2026-0262, a PAN-OS network traffic parsing denial-of-service issue.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
CSIRT Panamá issued an alert warning of active exploitation of CVE-2026-0257 in Palo Alto Networks PAN-OS GlobalProtect Portal and Gateway deployments. The notice described the authentication bypass mechanism and the risk of unauthorized VPN access to internal networks.
Rapid7 reported successful exploitation of CVE-2026-0257 against multiple customers beginning May 17, 2026. The attacks used infrastructure from Vultr and Dromatics Systems to target unpatched PAN-OS GlobalProtect deployments.
Palo Alto Networks published product advisories for CVE-2026-0257, a GlobalProtect authentication bypass vulnerability, and CVE-2026-0262, a PAN-OS denial-of-service issue. The advisories documented the vulnerabilities and associated remediation information.
The Dutch NCSC warned that CVE-2026-0257 is actively exploited and said exploitation requires reused HTTPS certificates plus an enabled authentication-override cookie setting. It advised prompt installation of Palo Alto updates and use of Rapid7 indicators of compromise; it also noted that public proof-of-concept code is available.
CISA added CVE-2026-0257 to its Known Exploited Vulnerabilities catalog after reports of active exploitation. The listing reflected the vulnerability's status as an exploited authentication bypass affecting Palo Alto Networks PAN-OS GlobalProtect.
Palo Alto Networks reported limited exploitation attempts against unpatched PAN-OS devices without mitigations during May 2026. The activity involved attempts to abuse the GlobalProtect authentication bypass flaw CVE-2026-0257.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
5 references tracked. Mallory keeps watching after this page renders.
cert.pa
Open sourcencsc.nl
Open sourcesecurity.paloaltonetworks.com
Open sourcesecurity.paloaltonetworks.com
Open sourcecve.circl.lu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.