Palo Alto VPN flaw actively exploited in the wild
TL;DR. Attackers exploit a critical authentication bypass vulnerability in Palo Alto GlobalProtect VPN, leading to unauthorized network access. - Rapid7 observed successful exploitation allowing unauthorized VPN sessions on affected PAN-OS systems since mid-May. - The flaw enables attackers to bypass authentication by manipulating override cookies, granting access to internal corporate networks. - CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, requiring federal agencies to patch systems. - Palo Alto Networks elevated the bug's severity rating following confirmed active exploitation reports from security researchers.
- Palo Alto Networks GlobalProtect VPN (PAN-OS) has a critical authentication bypass vulnerability (CVE-2026-0257).
- Rapid7 confirmed active exploitation of the flaw, enabling unauthorized VPN access and internal network access.
- The vulnerability allows attackers to create fake authentication override cookies by exploiting specific PAN-OS configurations.
- CISA added the flaw to its 'Known Exploited Vulnerabilities' catalog, urging immediate patching for federal agencies.
- Palo Alto revised its initial assessment, elevating the vulnerability's severity due to confirmed in-the-wild attacks.
Sources
- Palo Alto VPN bug graduates from advisory to active exploitation — theregister.com