logo

Palo Alto Warns of Exploitation of VPN Bypass Exploits (CVE-2026-0257) in PAN-OS Flaw

ID: 85e8da00-2933-56b0-9311-92f2bc19bfd5

STIX ID: report--85e8da00-2933-56b0-9311-92f2bc19bfd5

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-06-15

Date Updated: 2026-06-15

Author: Pierluigi Paganini

...
...

Palo Alto Networks and Rapid7 report active exploitation of CVE-2026-0257, a PAN-OS GlobalProtect authentication bypass that enables attackers to forge cookies (when the cookie encryption certificate is reused for HTTPS) and potentially gain VPN access to internal networks; Rapid7 observed at least two exploitation waves across multiple customers, published a proof-of-concept and IoCs (including several IPs, hostnames and MAC addresses), and recommends immediate patching or disabling the authentication-override feature / using a dedicated cookie certificate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.