Friday, September 11, 2026

Palo Alto Warns GlobalProtect VPN Flaw Is Being Actively Exploited

Palo Alto Networks has issued an urgent warning after confirming active exploitation of a GlobalProtect VPN vulnerability, tracked as CVE-2026-0257, impacting PAN-OS deployments with specific configurations.

The flaw, which affects the GlobalProtect portal and gateway components, enables an authentication bypass that allows unauthenticated attackers to establish VPN sessions and potentially gain access to internal enterprise networks.

Palo Alto Warns GlobalProtect VPN Flaw

According to Unit 42 researchers, the vulnerability stems from improper handling of authentication override cookies. In affected environments where the feature is enabled and misconfigured, attackers can forge authentication cookies and bypass standard login mechanisms.

This issue becomes exploitable when the same certificate is reused across multiple services, allowing adversaries to obtain the public key and craft valid authentication tokens. The vulnerability has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, confirming its use in real-world attacks.

Although initially assigned a CVSS score of 4.7 (medium severity), Palo Alto later revised the score to 7.8 (high severity) due to active exploitation and the critical nature of VPN edge devices.

Security researchers from Rapid7 observed exploitation attempts as early as May 17, 2026, affecting multiple organizations. In several cases, attackers successfully authenticated using forged cookies and established VPN tunnels without valid credentials. However, no significant post-exploitation activity or lateral movement has been widely observed so far.

Attackers are leveraging crafted HTTP POST requests to endpoints such as “/ssl-vpn/login.esp,” supplying malicious authentication cookies that are accepted without proper signature validation.

Once authenticated, additional requests to endpoints like “/ssl-vpn/getconfig.esp” and “/ssl-vpn/hipreport.esp” help establish a full VPN session.

Analysis indicates that attackers are abusing trust in decrypted cookie data, which is not cryptographically verified after decryption, effectively enabling arbitrary user impersonation.

PAN-OS Management Interface (Source: Palo Alto Network )
PAN-OS Management Interface (Source: Palo Alto Network )

Unit 42 noted that only a subset of targeted devices resulted in successful “gateway-connected” events, suggesting opportunistic scanning and exploitation attempts.

Organizations are advised to review GlobalProtect logs for suspicious login activity, particularly involving unusual host identifiers, generic device names, or anomalous authentication patterns such as empty domain fields and hardcoded client OS values like Windows 10.

Palo Alto Networks strongly recommends immediate patching or upgrading to fixed PAN-OS versions. As a temporary mitigation, organizations should turn off the authentication override feature or ensure that a dedicated certificate is used exclusively for cookie encryption and decryption.

Security teams are also encouraged to proactively hunt for indicators of compromise and initiate incident response procedures if suspicious VPN connections are detected.

Additionally, security tools such as Cortex XDR, XSIAM, and Advanced URL Filtering can help detect and block malicious activity associated with this vulnerability. Cortex Xpanse can identify exposed GlobalProtect portals and gateways, thereby reducing the attack surface.

Indicators of Compromise (IOCs)

Indicator TypeValue
IP Address23.128.228[.]6
IP Address104.207.144[.]154
IP Address146.19.216[.]119
IP Address146.19.216[.]120
IP Address146.19.216[.]125
IP Address179.43.172[.]213
IP Address185.195.232[.]139
IP Address198.12.106[.]60
IP Address202.144.192[.]47
MAC Addressaa:bb:cc:dd:ee:ff
MAC Address00:11:22:33:44:55
HostnameWINDOWS-LAPTOP-001
HostnameDESKTOP-GP01
HostnameGP-CLIENT

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

With exploitation ongoing and proof-of-concept code publicly available, organizations using GlobalProtect are at elevated risk. Immediate remediation, log analysis, and threat hunting are critical to prevent unauthorized network access and potential follow-on attacks.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News