An authentication bypass vulnerability, CVE-2026-0257, in Palo Alto Networks PAN-OS software is being actively exploited. Affecting the GlobalProtect portal and gateway features, the flaw allows a remote, unauthenticated attacker to forge a valid authentication cookie and gain unauthorized VPN access. While the vulnerability is configuration-dependent and rated as medium severity (CVSS 7.8), its active exploitation has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add it to its Known Exploited Vulnerabilities (KEV) catalog. Organizations using the affected products are urged to apply patches or mitigations immediately to prevent compromise of their network perimeter.
CVE-2026-0257 is an authentication bypass vulnerability affecting the GlobalProtect feature in PAN-OS and Prisma Access. The core issue lies in the improper handling of authentication override cookies under a specific, non-default configuration.
The vulnerability is under active, albeit limited, exploitation. Palo Alto Networks confirmed observing exploit attempts against unpatched devices. Security firm Rapid7 reported two distinct waves of exploitation on May 17 and May 21, 2026, likely from a single threat actor. While Rapid7 confirmed successful exploitation via forged cookies, they did not observe any post-exploitation lateral movement.
On May 29, 2026, CISA added CVE-2026-0257 to its KEV catalog, a strong indicator of credible, widespread risk. Federal agencies were directed to patch by June 1, 2026.
Despite the medium CVSS score, an authentication bypass on a perimeter security appliance like a VPN gateway should be treated as a critical risk. It provides a direct entry point into the corporate network for an unauthenticated attacker.
The following patterns may help identify vulnerable or compromised systems:
/global-protect/login.espauthentication-overrideauthentication-override is enabled and check if the associated certificate is reused elsewhere.D3-NTA).D3-ACH).Palo Alto Networks has provided several options for remediation. Organizations should prioritize these actions:
D3-SU).authentication-override to eliminate the attack vector.Given the KEV status, patching should be considered urgent and performed within emergency change control windows.
Severity of CVE-2026-0257 escalated to critical due to active exploitation. New MITRE ATT&CK techniques and enhanced detection methods provided.
Apply the security patches provided by Palo Alto Networks to fix the vulnerability.
If patching is not possible, apply the recommended configuration changes, such as using a dedicated certificate for cookie encryption.
Restrict access to the GlobalProtect portal from untrusted IP addresses if possible, reducing the attack surface.
Palo Alto Networks first discloses CVE-2026-0257.
First wave of exploitation observed by Rapid7.
Second wave of exploitation observed by Rapid7.
CISA adds CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) catalog.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.