HomeSecurityPalo Alto: Active exploitation of GlobalProtect VPN vulnerability

Palo Alto: Active exploitation of GlobalProtect VPN vulnerability

Palo Alto Networks is warning of active exploitation of a critical vulnerability, CVE-2026-0257, affecting the GlobalProtect VPN systems. Unknown attackers are exploiting this vulnerability to gain unauthorized access to corporate networks via GlobalProtect portals. The incident represents one of the most serious threats facing companies that rely on VPN solutions to secure their remote workers.

Palo Alto: Active exploitation of GlobalProtect VPN vulnerability

The vulnerability , CVE-2026-0257, has a CVSS score of 7.8 and is related to an authentication bypass affecting the portal and gateway components of the PAN-OS software . According to the company, the flaw allows malicious actors to bypass security measures and establish unauthorized VPN connections . The severity of the problem is amplified by the fact that attackers do not need valid credentials to gain access to the organizations' internal network.

The first signs of active exploitation were observed on May 17, 2026, with limited attacks targeting specific systems. Palo Alto Networks says that “no malicious post-access or lateral movement has been detected to date,” and only a small fraction of the targeted devices have been able to establish actual VPN sessions. Despite the limited success of the attacks, security experts warn that the situation could rapidly escalate as more attackers gain knowledge of the exploit technique.

Technical details of the GlobalProtect vulnerability

The vulnerability, CVE-2026-0257, exploits a critical weakness in the way PAN-OS handles authentication override cookies. The problem occurs when the same certificate is used for both HTTPS services and for encrypting authentication cookies. This practice, often adopted for ease of administration, creates a serious security hole that can be exploited by anyone with access to the public key.

See also: Palo Alto Networks: Brute-force attempts against PAN-OS GlobalProtect gateways

Attackers can retrieve the public key via a normal HTTPS session and then use it to forge valid authentication override cookies for any user, including the local administrator. The system decrypts and accepts these forged cookies without performing signature verification. This process allows malicious actors to impersonate legitimate users with full access rights.

Government response and criticality

The US Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability CVE-2026-0257 to the Known Exploited Vulnerabilities (KEV) list on May 29, 2026 , ordering federal agencies to address the bug by June 1, 2026. CISA 's decision to include the vulnerability on the KEV list signals the immediate and widespread threat it poses to critical infrastructure in the United States.

See also: New attacks target Palo Alto Networks' GlobalProtect portals

Palo Alto Networks GlobalProtect VPN vulnerability cybersecurity

Impacts for the Greek market and European businesses

The CVE-2026-0257 vulnerability is of particular importance to Greek and European enterprises that have widely adopted Palo Alto NetworksGlobalProtect solutions to support remote work. With the increased reliance on VPN technologies following the pandemic, thousands of organizations in Europe may be exposed to this threat.

See also: NATO: Cybersecurity partnerships with Microsoft, Palo Alto Networks and ESET

Greek businesses using PAN-OS versions 11.2.0 to 11.2.11 and 12.1.4 to 12.1.4-h5 should act immediately. Delaying the implementation of fixes could lead to serious data breaches, especially in industries such as banking, telecommunications and government agencies that are preferred targets of attackers.

Immediate protective measures and recommendations

Organizations using GlobalProtect VPN appliances should take immediate action. Palo Alto Networks recommends immediately upgrading PAN-OS to versions 11.2.12 or 12.1.4-h6 (or later) that include the fix for the vulnerability. Patching should be done during off-peak hours to avoid disruption to business operations.

In case immediate patching is not possible, organizations can completely disable the “Authentication Override” feature in the GlobalProtect portal and gateway. Alternatively, they can create a new certificate exclusively for authentication override cookies, without sharing it with other services.

Palo Alto PAN-OS vulnerability CVE-2026-0300 cybersecurity

The company has also published indicators of breach (IoCs) related to the activity:

IP addresses –

  • 23.128.228[.]6
  • 104.207.144[.]154
  • 146.19.216[.]119
  • 146.19.216[.]120
  • 146.19.216[.]125
  • 179.43.172[.]213
  • 185.195.232[.]139
  • 198.12.106[.]60
  • 202.144.192[.]47

Host Names and MAC Addresses –

  • aa:bb:cc:dd:ee:ff
  • 00:11:22:33:44:55
  • WINDOWS-LAPTOP-001
  • DESKTOP-GP01
  • GP-CLIENT

Palo Alto Networks also urges customers to search GlobalProtect logs for gateway-connected events that match hard-coded client configuration values ​​from one of the following:

  • endpoint_os_version : Microsoft Windows 10 Pro 64-bit
  • source_user_info.domain : empty

According to The Hacker News, the vulnerability poses a serious threat to the security of corporate networks and requires immediate action from system administrators. Rapid response and implementation of appropriate protection measures are critical to avoid potential breaches that could have devastating consequences for affected organizations.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS