logo

Arctic Wolf Observes an Increase in Palo Alto Networks GlobalProtect Authentication Bypass Exploitation via CVE-2026-0257

ID: ae9297c0-a024-5701-b964-24e67e6491a6

STIX ID: report--ae9297c0-a024-5701-b964-24e67e6491a6

Feed Name: Arctic Wolf Blog

Threat Score
72/100

Date Published: 2026-06-11

Date Updated: 2026-06-11

...
...

Arctic Wolf observed an active exploitation campaign targeting CVE-2026-0257 (GlobalProtect authentication bypass) beginning mid-May 2026 and accelerating late May–early June after public proof-of-concept code appeared; attackers forged authentication-override cookies to establish unauthorized IPSec VPN sessions (primarily from VPS hosting ASNs) and, in a subset of intrusions, quickly performed internal SMB/NTLM reconnaissance consistent with Impacket tooling. The report includes exploitation patterns, example indicators (IP addresses, ASNs, device name artifacts), detection guidance, and mitigation priorities for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.