Arctic Wolf Observes an Increase in Palo Alto Networks GlobalProtect Authentication Bypass Exploitation via CVE-2026-0257
ID: ae9297c0-a024-5701-b964-24e67e6491a6
STIX ID: report--ae9297c0-a024-5701-b964-24e67e6491a6
Feed Name: Arctic Wolf Blog
Arctic Wolf observed an active exploitation campaign targeting CVE-2026-0257 (GlobalProtect authentication bypass) beginning mid-May 2026 and accelerating late May–early June after public proof-of-concept code appeared; attackers forged authentication-override cookies to establish unauthorized IPSec VPN sessions (primarily from VPS hosting ASNs) and, in a subset of intrusions, quickly performed internal SMB/NTLM reconnaissance consistent with Impacket tooling. The report includes exploitation patterns, example indicators (IP addresses, ASNs, device name artifacts), detection guidance, and mitigation priorities for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
