BlackTree Security · Infrastructure · Automation · AI

The VPN Accepted the Cookie. The Attacker Entered Without Credentials.

An authentication bypass in Palo Alto Networks GlobalProtect was exploited against multiple organizations before a public proof of concept made the weakness broadly reproducible. The flaw let an unauthenticated attacker present a forged cookie and, in successful cases, obtain an internal VPN address.

Palo Alto Networks disclosed CVE-2026-0257 on 13 May 2026. It affects the GlobalProtect portal and gateway in vulnerable PAN-OS and Prisma Access releases when authentication-override cookies are enabled in a susceptible configuration. Panorama and Cloud NGFW are not affected.

Rapid7 later identified successful exploitation across numerous managed-detection customers, with the earliest activity dated 17 May. Palo Alto Networks confirmed limited exploit attempts on unpatched systems without mitigations, and CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on 29 May.

The VPN accepted a cookie that should not have been trusted

GlobalProtect authentication override lets a portal or gateway issue a cookie after a legitimate login. The user can present that cookie during a later connection instead of authenticating again. In effect, the cookie becomes a bearer credential, so its integrity and the isolation of the certificate that protects it are security boundaries.

With CVE-2026-0257, an attacker can bypass those checks and establish an unauthorized VPN connection. Rapid7 observed suspicious cookie authentication to local administrator accounts across several customer environments. Its researchers validated the technique with a successful proof of concept.

The observed campaign came in at least two waves. On 18 May, Rapid7 saw suspicious cookie logins originating from infrastructure at Vultr. On 21 May, a second wave used different hosting infrastructure but repeated distinctive device identifiers. In that later activity, some systems assigned the attacker a VPN address and provided access to the internal network.

Not every forged authentication produced a working tunnel. Rapid7 said appliances accepted the cookie but did not establish a full VPN session in eight of ten affected customer environments. Palo Alto Networks Unit 42 likewise reported that only a small portion of probed devices reached a successful gateway-connected event. Neither team had identified lateral movement in the activity it had investigated at the time of publication.

A configuration-dependent flaw can still be an edge emergency

The vulnerability is not exposed by every default installation. Affected environments used GlobalProtect authentication override, and Rapid7’s cases had Cloud Authentication Service disabled. That prerequisite narrows the population, but it does not reduce the consequence for a matching deployment. The vulnerable service is an enterprise access gateway, and successful exploitation crosses directly from the public internet into a private network.

The episode also shows the limits of a static severity score. Palo Alto Networks initially rated the issue medium at 4.7. After public exploitation and proof-of-concept evidence, it raised the score to 7.8 high and assigned its highest response urgency. Rapid7 argued that defenders should treat an authentication bypass on an edge-facing VPN as critical in practice.

Upgrade every portal and gateway in the trust chain

Palo Alto Networks has fixed releases across the supported PAN-OS 10.2, 11.1, 11.2, and 12.1 branches, plus affected Prisma Access 10.2 and 11.2 versions. Administrators should use the vendor’s version table because the correct hotfix depends on the branch.

Environments that use authentication-override cookies should upgrade all portals and gateways that generate or accept them. A partial rollout can create cookie-compatibility problems. After the upgrade, users will need to authenticate once so that cookies are regenerated with the stronger method.

If immediate patching is impossible, the vendor recommends disabling authentication override or creating a new certificate dedicated exclusively to authentication-override cookies. A certificate previously shared with another service should not be reused. Strict HMAC validation must be enabled again after any phased upgrade is complete.

Incident review is as important as patching. Defenders should search GlobalProtect authentication logs for successful cookie-based logins, unexpected device names or MAC addresses, and gateway-connected events associated with the indicators published by Unit 42 and Rapid7. A successful VPN assignment should trigger investigation of the connected session even when no lateral movement is immediately visible.

Sources: Palo Alto Networks security advisory, initially published 13 May 2026 and updated 29 May 2026; Rapid7 exploitation analysis, published 29 May 2026 and updated through 3 June 2026; Palo Alto Networks Unit 42 threat brief, updated 9 June 2026 at 11:45 a.m. PT; CISA Known Exploited Vulnerabilities Catalog, entry added 29 May 2026. Initial source times were not provided where only a date is shown.

Leave a Reply

Your email address will not be published. Required fields are marked *