logo

Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks

ID: afd02728-bc14-57d1-b0b2-d74a25b06573

STIX ID: report--afd02728-bc14-57d1-b0b2-d74a25b06573

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-05-30

Date Updated: 2026-05-30

Author: Lawrence Abrams

...
...

Palo Alto Networks and Rapid7 report active exploitation of PAN-OS GlobalProtect CVE-2026-0257, an authentication override cookie validation flaw that can let attackers forge cookies to authenticate to VPN gateways; Rapid7 observed exploitation from May 17–21, created a PoC, and CISA added the vulnerability to its KEV, while recommended mitigations include installing vendor patches, disabling authentication override cookies, or using separate certificates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.