Palo Alto Networks GlobalProtect Vulnerability Disclosed
Palo Alto Networks has issued a security advisory regarding a significant authentication bypass vulnerability, identified as CVE-2026-0257, impacting its GlobalProtect portal and gateway components. This critical flaw affects various versions of PAN-OS (10.2, 11.1, 11.2, and 12.1) as well as Prisma Access (10.2 and 11.2). The vulnerability allows malicious actors to remotely forge authentication override cookies, thereby establishing complete VPN sessions without requiring any user credentials or interaction.
Security researchers have confirmed that active exploitation of this vulnerability has been observed in the wild, with initial intrusions detected as early as May 17, 2026, followed by a second wave of exploitation on May 21. This indicates a pressing need for organizations utilizing the affected Palo Alto Networks products to apply necessary patches and mitigations immediately to prevent potential unauthorized access to their networks.
The nature of this vulnerability, enabling unauthenticated access to VPN resources, poses a severe risk to network security and data integrity. Organizations are urged to review their GlobalProtect configurations, monitor their networks for any suspicious activity, and prioritize the implementation of security updates to address this critical exposure.
Read original source