Palo Alto Networks PAN-OS / Prisma Access GlobalProtect Authentication Bypass (CVE-2026-0257) — Active Exploitation, CISA KEV

Palo Alto Networks PAN-OS / Prisma Access GlobalProtect (TL-2026-0631) is a critical-severity software vulnerability scored CVSS 7.8, first published 2026-05-29 and last reviewed 2026-07-22. It has no confirmed attribution, affects Palo Alto Networks PAN-OS 12.1, references 1 CVE (CVE-2026-0257), maps to 27 MITRE ATT&CK techniques (T1003, T1016, T1020), and is covered by 9 detection rules and 48 indicators of compromise.

Key facts for TL-2026-0631

Threat ID
TL-2026-0631
Severity
CRITICAL
CVSS
7.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/E:A/AU:N/R:A/V:D/RE:M/U:Red)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-05-29
Last reviewed
2026-07-22
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Detection rules
9
Indicators of compromise
48
Updates
2026-07-22 · revalidated 1× · latest source

CVE-2026-0257 is an authentication bypass in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS and Prisma Access. When Cloud Authentication Service (CAS) is disabled and authentication-override cookies are enabled with a reused certificate, a remote, unauthenticated attacker can forge or replay an auth-override cookie and establish an unauthorized VPN connection. CISA added it to the KEV catalog on 2026-05-29 (remediation due 2026-06-01) after Rapid7 MDR observed in-the-wild exploitation across multiple customers in two waves beginning 2026-05-17.

How Palo Alto Networks PAN-OS / Prisma Access GlobalProtect works

CVE-2026-0257 is an authentication bypass affecting the GlobalProtect portal and gateway components of Palo Alto Networks PAN-OS software and Prisma Access. Panorama and Cloud NGFW are not impacted. Palo Alto Networks published the advisory on 2026-05-13 and classifies the flaw as CWE-565 (Reliance on Cookies without Validation and Integrity Checking), assigning a CVSS v4.0 base score of 7.8 (HIGH). No CVSS v3.1 metrics were issued. Although the numeric score is HIGH rather than CRITICAL, CISA's KEV addition and Rapid7 both urge organizations to treat the issue as critical because it is an unauthenticated authentication bypass on an internet-facing enterprise VPN appliance under active exploitation.

Exploitation requires a specific, but not uncommon, configuration: the GlobalProtect portal or gateway must have Cloud Authentication Service (CAS) disabled, authentication-override cookies enabled (cookie generation and acceptance), and the authentication-override encryption certificate reused/shared with the HTTPS service certificate. Under these conditions the integrity of the authentication-override (auth) cookie is not properly validated, allowing a remote unauthenticated attacker to forge or replay a valid session cookie, bypass GlobalProtect authentication, and bring up a VPN tunnel through the gateway. In a subset of wave-2 victims this resulted in the attacker being assigned an internal VPN IP address.

Rapid7 MDR observed in-the-wild exploitation across multiple customer environments. The earliest activity was observed on 2026-05-17; the first MDR alert fired on 2026-05-18 at 01:51:37 UTC under the rule "Suspicious VPN Authentication - Local Account Logon via Generic Non-Human Identity." Attackers performed suspicious cookie authentication to the local admin account. Wave 1 originated from the hosting provider Vultr (source IP 104.207.144.154) and presented the Linux client hostname GP-CLIENT. A second wave on 2026-05-21 originated from the hosting provider Dromatics Systems (source IPs 146.19.216.125, 146.19.216.119, 146.19.216.120 within 146.19.216.0/24) and presented the Windows client hostname DESKTOP-GP01. A consistent spoofed MAC address (aa:bb:cc:dd:ee:ff) was observed across both waves, suggesting a single threat actor reusing tooling. Rapid7 did not observe successful lateral movement from the compromised devices in most cases.

BeaconBeagle lookups performed during research (2026-05-29) returned no known C2 beacon match for any of the four source IPs, consistent with these being attacker-controlled hosting/VPS exploitation sources rather than persistent command-and-control infrastructure.

Remediation: apply the fixed PAN-OS / Prisma Access versions, or, where patching is not immediately possible, apply the official workarounds — disable the Authentication Override options (generate and accept cookies) in the GlobalProtect portal and gateway configuration, and/or use a dedicated certificate exclusively for authentication-override cookies. Re-enabling Cloud Authentication Service also removes the vulnerable condition. CISA BOD 22-01 requires federal agencies to remediate by 2026-06-01.

MITRE ATT&CK techniques used in TL-2026-0631

Credential Access

T1003 OS Credential Dumping; T1539 Steal Web Session Cookie; T1606 Forge Web Credentials

Discovery

T1016 System Network Configuration Discovery; T1046 Network Service Discovery; T1087 Account Discovery

Exfiltration

T1020 Automated Exfiltration; T1567 Exfiltration Over Web Service

Lateral Movement

T1021 Remote Services

Defense Evasion

T1036 Masquerading; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information

Persistence

T1053 Scheduled Task/Job; T1078 Valid Accounts; T1547 Boot or Logon Autostart Execution

Collection

T1074 Data Staged

Initial Access

T1133 External Remote Services; T1190 Exploit Public-Facing Application

Command and Control

T1219 Remote Access Tools; T1572 Protocol Tunneling

Impact

T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery

lateral-movement

T1550 Use Alternate Authentication Material

defense-impairment

T1556 Modify Authentication Process; T1685 Disable or Modify Tools

Resource Development

T1583 Acquire Infrastructure

Reconnaissance

T1595 Active Scanning

Affected products and versions in Palo Alto Networks PAN-OS / Prisma Access GlobalProtect

  • Palo Alto Networks — PAN-OS 12.1
    Vulnerable versions: < 12.1.4-h6; < 12.1.7
    Fixed in: 12.1.4-h6; 12.1.7
  • Palo Alto Networks — PAN-OS 11.2
    Vulnerable versions: < 11.2.4-h17; < 11.2.7-h14; < 11.2.10-h7; < 11.2.12
    Fixed in: 11.2.4-h17; 11.2.7-h14; 11.2.10-h7; 11.2.12
  • Palo Alto Networks — PAN-OS 11.1
    Vulnerable versions: < 11.1.4-h33; < 11.1.6-h32; < 11.1.7-h6; < 11.1.10-h25; < 11.1.13-h5; < 11.1.15
    Fixed in: 11.1.4-h33; 11.1.6-h32; 11.1.7-h6; 11.1.10-h25; 11.1.13-h5; 11.1.15
  • Palo Alto Networks — PAN-OS 10.2
    Vulnerable versions: affected 10.2 maintenance releases
    Fixed in: applicable fixed 10.2 maintenance release
  • Palo Alto Networks — Prisma Access 10.2
    Vulnerable versions: < 10.2.10-h36
    Fixed in: 10.2.10-h36
  • Palo Alto Networks — Prisma Access 11.2
    Vulnerable versions: < 11.2.7-h13
    Fixed in: 11.2.7-h13

Remediation for Palo Alto Networks PAN-OS / Prisma Access GlobalProtect

Patches

  • PAN-OS 12.1: upgrade to 12.1.4-h6, 12.1.7 or later.
  • PAN-OS 11.2: upgrade to 11.2.4-h17, 11.2.7-h14, 11.2.10-h7, 11.2.12 or later.
  • PAN-OS 11.1: upgrade to 11.1.4-h33, 11.1.6-h32, 11.1.7-h6, 11.1.10-h25, 11.1.13-h5, 11.1.15 or later.
  • PAN-OS 10.2: upgrade to the applicable fixed maintenance release.
  • Prisma Access 10.2: fixed in 10.2.10-h36 or later.
  • Prisma Access 11.2: fixed in 11.2.7-h13 or later.

Immediate actions

  • Apply mitigations per Palo Alto Networks instructions before the CISA BOD 22-01 due date of 2026-06-01, or discontinue use of the product if mitigations are unavailable.
  • Block the known wave-1 and wave-2 source IPs (104.207.144.154; 146.19.216.119; 146.19.216.120; 146.19.216.125) and the 146.19.216.0/24 range at the perimeter.
  • Audit GlobalProtect authentication logs for cookie authentication to the local admin account, logins from default/spoofed hostnames (GP-CLIENT, DESKTOP-GP01), and the spoofed MAC aa:bb:cc:dd:ee:ff.

Workarounds

  • Disable the Authentication Override options (generate and accept cookies) in the GlobalProtect portal and gateway configuration.
  • Use a dedicated certificate exclusively for Authentication Override cookies instead of reusing the HTTPS service certificate.

Longer-term hardening

  • Re-enable Cloud Authentication Service (CAS) where feasible to remove the vulnerable condition.
  • Continuously monitor GlobalProtect cookie-based authentication events and alert on local-account VPN logons from non-human identities.
  • Rotate any certificate that was shared between the authentication-override function and the HTTPS service.
  • Apply network segmentation so a compromised VPN session has limited reachability.

CVEs associated with Palo Alto Networks PAN-OS / Prisma Access GlobalProtect

CVE-2026-0257

Weaknesses (CWE) in Palo Alto Networks PAN-OS / Prisma Access GlobalProtect

CWE-565

Timeline of Palo Alto Networks PAN-OS / Prisma Access GlobalProtect

  • Palo Alto Networks published the security advisory for CVE-2026-0257 (CVSS v4.0 7.8 HIGH, CWE-565).
  • Earliest in-the-wild exploitation observed by Rapid7 MDR against affected GlobalProtect appliances.
  • First Rapid7 MDR alert at 01:51:37 UTC ('Suspicious VPN Authentication - Local Account Logon via Generic Non-Human Identity'); wave 1 from Vultr source IP 104.207.144.154, client hostname GP-CLIENT.
  • Second exploitation wave from Dromatics Systems source IPs (146.19.216.0/24), client hostname DESKTOP-GP01; same spoofed MAC aa:bb:cc:dd:ee:ff observed across both waves.
  • As of 2026-05-29, CVE-2026-0257 remains an active threat: it sits in CISA KEV (added 2026-05-29) and Palo Alto plus Rapid7 confirm ongoing in-the-wild exploitation of unpatched/unmitigated GlobalProtect appliances across two waves by a single actor. Patches and workarounds exist but the unauthenticated VPN auth-bypass is still being exploited; no takedown or disruption reported.
  • NVD record last modified; status 'Undergoing Analysis'. BeaconBeagle returned no C2 beacon match for any of the four known source IPs.
  • CISA added CVE-2026-0257 to the Known Exploited Vulnerabilities catalog (catalog version 2026.05.29).
  • SecurityWeek reports the vulnerability has been under exploitation for weeks across multiple organizations.
  • CISA BOD 22-01 remediation deadline for CVE-2026-0257.
  • Palo Alto Networks updates advisory with mitigation guidance including dedicated-certificate workaround.
  • Unit42 and Rapid7 publish detailed threat briefs on exploitation patterns and IOCs.
  • Arctic Wolf Labs begins investigating multiple June 2026 intrusions traced to CVE-2026-0257 exploitation leading to Qilin ransomware deployment.
  • Arctic Wolf Labs publishes 'Cookie Crumbles' report detailing the full attack chain from VPN bypass to Qilin ransomware detonation.
  • The Hacker News and Security Affairs report widely on Qilin affiliates abusing CVE-2026-0257 for initial access.

Update history for TL-2026-0631

Sources cited for Palo Alto Networks PAN-OS / Prisma Access GlobalProtect

Threats related to Palo Alto Networks PAN-OS / Prisma Access GlobalProtect

Detection coverage for TL-2026-0631

As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0631 across Splunk SPL, Microsoft KQL and Sigma, covering 48 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats