Palo Alto Networks has issued an urgent warning after confirming active exploitation of a GlobalProtect VPN vulnerability, tracked as CVE-2026-0257, impacting PAN-OS deployments with specific configurations.
The flaw, which affects the GlobalProtect portal and gateway components, enables an authentication bypass that allows unauthenticated attackers to establish VPN sessions and potentially gain access to internal enterprise networks.
Palo Alto Warns GlobalProtect VPN Flaw
According to Unit 42 researchers, the vulnerability stems from improper handling of authentication override cookies. In affected environments where the feature is enabled and misconfigured, attackers can forge authentication cookies and bypass standard login mechanisms.
This issue becomes exploitable when the same certificate is reused across multiple services, allowing adversaries to obtain the public key and craft valid authentication tokens. The vulnerability has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, confirming its use in real-world attacks.
Although initially assigned a CVSS score of 4.7 (medium severity), Palo Alto later revised the score to 7.8 (high severity) due to active exploitation and the critical nature of VPN edge devices.
Security researchers from Rapid7 observed exploitation attempts as early as May 17, 2026, affecting multiple organizations. In several cases, attackers successfully authenticated using forged cookies and established VPN tunnels without valid credentials. However, no significant post-exploitation activity or lateral movement has been widely observed so far.
Attackers are leveraging crafted HTTP POST requests to endpoints such as “/ssl-vpn/login.esp,” supplying malicious authentication cookies that are accepted without proper signature validation.
Once authenticated, additional requests to endpoints like “/ssl-vpn/getconfig.esp” and “/ssl-vpn/hipreport.esp” help establish a full VPN session.
Analysis indicates that attackers are abusing trust in decrypted cookie data, which is not cryptographically verified after decryption, effectively enabling arbitrary user impersonation.

Unit 42 noted that only a subset of targeted devices resulted in successful “gateway-connected” events, suggesting opportunistic scanning and exploitation attempts.
Organizations are advised to review GlobalProtect logs for suspicious login activity, particularly involving unusual host identifiers, generic device names, or anomalous authentication patterns such as empty domain fields and hardcoded client OS values like Windows 10.
Palo Alto Networks strongly recommends immediate patching or upgrading to fixed PAN-OS versions. As a temporary mitigation, organizations should turn off the authentication override feature or ensure that a dedicated certificate is used exclusively for cookie encryption and decryption.
Security teams are also encouraged to proactively hunt for indicators of compromise and initiate incident response procedures if suspicious VPN connections are detected.
Additionally, security tools such as Cortex XDR, XSIAM, and Advanced URL Filtering can help detect and block malicious activity associated with this vulnerability. Cortex Xpanse can identify exposed GlobalProtect portals and gateways, thereby reducing the attack surface.
Indicators of Compromise (IOCs)
| Indicator Type | Value |
|---|---|
| IP Address | 23.128.228[.]6 |
| IP Address | 104.207.144[.]154 |
| IP Address | 146.19.216[.]119 |
| IP Address | 146.19.216[.]120 |
| IP Address | 146.19.216[.]125 |
| IP Address | 179.43.172[.]213 |
| IP Address | 185.195.232[.]139 |
| IP Address | 198.12.106[.]60 |
| IP Address | 202.144.192[.]47 |
| MAC Address | aa:bb:cc:dd:ee:ff |
| MAC Address | 00:11:22:33:44:55 |
| Hostname | WINDOWS-LAPTOP-001 |
| Hostname | DESKTOP-GP01 |
| Hostname | GP-CLIENT |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
With exploitation ongoing and proof-of-concept code publicly available, organizations using GlobalProtect are at elevated risk. Immediate remediation, log analysis, and threat hunting are critical to prevent unauthorized network access and potential follow-on attacks.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.





