Palo Alto Warns of Exploitation of VPN Bypass Exploits (CVE-2026-0257) in PAN-OS Flaw
ID: 85e8da00-2933-56b0-9311-92f2bc19bfd5
STIX ID: report--85e8da00-2933-56b0-9311-92f2bc19bfd5
Feed Name: Security Affairs
Palo Alto Networks and Rapid7 report active exploitation of CVE-2026-0257, a PAN-OS GlobalProtect authentication bypass that enables attackers to forge cookies (when the cookie encryption certificate is reused for HTTPS) and potentially gain VPN access to internal networks; Rapid7 observed at least two exploitation waves across multiple customers, published a proof-of-concept and IoCs (including several IPs, hostnames and MAC addresses), and recommends immediate patching or disabling the authentication-override feature / using a dedicated cookie certificate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
