logo

CVE-2026-0257: Rapid7 Caught Attackers Abusing Forged VPN Cookies Against Multiple Customers

ID: efb25bed-58e1-5d10-8fe3-585f11ad5523

STIX ID: report--efb25bed-58e1-5d10-8fe3-585f11ad5523

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2026-05-31

Date Updated: 2026-06-01

Author: Pierluigi Paganini

...
...

Rapid7 confirmed active exploitation of CVE-2026-0257 in Palo Alto GlobalProtect: attackers can forge auth cookies (when a cookie encryption certificate is reused with HTTPS) to bypass VPN authentication and in some cases obtain internal network access; Rapid7 observed two exploitation waves starting May 17, published a PoC and IoCs, and recommends patching or disabling the authentication-override feature or using a dedicated cookie certificate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.