Palo Alto VPN flaw actively exploited in the wild

TL;DR. Attackers exploit a critical authentication bypass vulnerability in Palo Alto GlobalProtect VPN, leading to unauthorized network access. - Rapid7 observed successful exploitation allowing unauthorized VPN sessions on affected PAN-OS systems since mid-May. - The flaw enables attackers to bypass authentication by manipulating override cookies, granting access to internal corporate networks. - CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, requiring federal agencies to patch systems. - Palo Alto Networks elevated the bug's severity rating following confirmed active exploitation reports from security researchers.

Sources

Back to QLANKR News