Attackers are actively exploiting CVE-2026-0257 in Palo Alto Networks PAN-OS and Prisma Access GlobalProtect deployments to bypass authentication and gain unauthorized VPN access. The flaw affects environments where the non-default authentication override feature is enabled and the cookie encryption certificate is improperly reused with another service such as HTTPS, allowing a remote unauthenticated attacker to forge authentication override cookies. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, while Rapid7 reported exploitation beginning as early as May 17 and observed additional activity on May 21.
Rapid7 said some intrusions resulted in full VPN IP assignments and direct access to internal networks, with two of ten impacted MDR customer environments showing successful attacker VPN sessions. Investigators linked multiple waves of activity to the same threat actor based on recurring artifacts including spoofed MAC address aa:bb:cc:dd:ee:ff and hostnames such as GP-CLIENT and DESKTOP-GP01, with attack infrastructure hosted at Vultr and later Dromatics Systems. Palo Alto Networks has released patches, and defenders are being urged to upgrade immediately, disable authentication override if it is not required, use a dedicated certificate exclusively for authentication override cookies, and hunt for the published indicators of compromise.

See which actors are running it and whether you're in range.
11 events from the most recent confirmed update back to the earliest known activity.
Following CISA's addition of CVE-2026-0257 to the KEV catalog, federal civilian agencies were required to remediate the Palo Alto Networks authentication bypass vulnerability by June 19, 2026. The reference also emphasized that unsupported PAN-OS 9.0, 9.1, and 10.0 versions remain vulnerable and will not receive fixes.
Palo Alto Networks Unit 42 warned that an unidentified threat actor was probing GlobalProtect-enabled devices at scale for CVE-2026-0257, with only a small subset of targets resulting in successful gateway-connected events. The company also published network and host-based indicators and said no confirmed lateral movement or data exfiltration had been observed.
FortiGuard Labs reported that exploitation of Palo Alto Networks GlobalProtect authentication bypass CVE-2026-0257 was still ongoing against exposed services as of June 9, 2026. The alert reiterated that attackers could establish unauthorized VPN sessions and conduct follow-on activity inside victim networks.
Arctic Wolf reported that exploitation of Palo Alto Networks GlobalProtect authentication bypass CVE-2026-0257 increased sharply from May 30, 2026, following public release of technical details and proof-of-concept code. In some intrusions, attackers established unauthorized IPSec tunnels and performed internal SMB and NTLM reconnaissance after gaining VPN access.
Bishop Fox published analysis showing how CVE-2026-22557 could be used to steal UniFi controller backups, databases, and TLS keystores, potentially leading to controller takeover and compromise of managed devices. The firm also released a safe detection tool and highlighted patched UniFi versions.
Rapid7 publicly reported active exploitation of CVE-2026-0257, confirmed the issue with a proof of concept, and published a testing script. The company said attackers obtained VPN sessions in 2 of 10 impacted MDR customer environments, though no lateral movement was observed.
CISA added CVE-2026-0257 to its Known Exploited Vulnerabilities catalog on May 29, 2026. The listing reflected active in-the-wild exploitation of the Palo Alto Networks authentication bypass flaw.
Additional exploitation activity was observed on May 21, 2026, against vulnerable GlobalProtect deployments. Reporting linked both waves to the same threat actor based on consistent artifacts such as a spoofed MAC address and recurring hostnames.
Rapid7 observed exploitation of Palo Alto Networks PAN-OS/Prisma Access GlobalProtect authentication bypass CVE-2026-0257 beginning as early as May 17, 2026. The activity targeted deployments with authentication override enabled and a reused cookie-encryption certificate.
Palo Alto Networks released fixes for CVE-2026-0257 on May 13, 2026. The authentication bypass flaw affects PAN-OS GlobalProtect portal and gateway deployments under specific configurations involving authentication override cookies and certificate reuse.
Ubiquiti disclosed CVE-2026-22557 on March 18, 2026, as part of security bulletin SAB-062. The flaw affects the UniFi Network Application guest captive portal and was later described by Bishop Fox as an unauthenticated path traversal issue.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
23 references tracked. Mallory keeps watching after this page renders.
codeby.net
Open sourcecisecurity.org
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcethecyberthrone.in
Open sourcerapid7.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.