Cyber security alert: active operation of CVE-2026-0257 in PAN-OS GlobalProtect allows authentication without credentials

Author: Published 4 min de lectura 229 reading

The images in this article were generated with artificial intelligence. How we publish

Palo Alto Networks has warned that active vulnerable holdings CVE-2026-0257 are already being observed in PAN-OS, related to the GlobalProtect portal and gateway. Initially catalogued as medium gravity because it requires specific configurations - such as the use of authentication cancellation cookies (authenization override cookies) and a specific certificate configuration - the company raised the rating to High after detecting attempts at exploitation against unpatched devices.

The technical vector of the failure is significant from the operational point of view: PAN-OS disfigures the authentication cancellation cookies with a private key configured and trust in its content without verifying the signature. If the same certificate is used for HTTPS services and for these cookies, an attacker can obtain the public certificate through the HTTPS session and manufacture signed cookies that the device will accept as valid. Rapid7 published a PoC that demonstrates this flow and documented operating observations since May 17- 18, including infrastructure in public hosting providers such as Vultr and Dromatics Systems; Rapid7's notice includes technical details and chronology: Rapid7 analysis.

Cyber security alert: active operation of CVE-2026-0257 in PAN-OS GlobalProtect allows authentication without credentials
Image generated with IA.

That this vulnerability has been included in the CISA catalogue of exploited vulnerabilities (Known Exploited Vulnerabilities) implies a specific regulatory pressure: the U.S. federal agencies. The US must implement mitigation quickly, and many private organizations must treat it with the same priority. The entry to the catalogue is available here: CISA KEV. For the official technical reference on the CVE, the NVD tab provides details and numbering: CVE-2026-0257 in NVD.

From a risk perspective, there are two clear messages: first, the holding allows authentication without valid credentials in the VPN component, with the possibility of reaching domestic remedies if the attacker is able to set up the full session; second, although Rapid7 reports that in many cases the VPN session was not completed, the acceptance of the forged cookie already constitutes a commitment to the authentication process and must be treated as such until proven otherwise by forensic investigation.

The immediate actions to be taken by security teams are clear and urgent. First of all, apply the official patches of Palo Alto as soon as possible; the patch is the final correction. If for compatibility reasons it is not feasible to update immediately, temporary mitigation should be applied: disable the functionality of authentication override cookies, or ensure that the certificate used for cookies is exclusive and not reused for HTTPS services. Palo Alto maintains a communication with the instructions that should be followed step by step.

In addition to the patch and the mitigations in the application, a detection and response work is essential: to review GlobalProtect log for unusual authentication attempts, to search for established sessions from recent external PIs associated with observed vectors and to audit changes in administrative accounts. If there is a suspicion of unauthorized access, it is appropriate to isolate the affected equipment from the internal network, preserve disk images and memory spins and activate a digital response process coordinated with the forensic team.

Cyber security alert: active operation of CVE-2026-0257 in PAN-OS GlobalProtect allows authentication without credentials
Image generated with IA.

Additional safety measures should not be forgotten: network segmentation to limit the scope of a compromised VPN, tightening of remote management (administrative access limited by separate IP or VPN control lists), and key / certificate rotation if there is a possibility that they have been exfiltered. Implementing or strengthening behavior monitoring controls and specific alerts for unexpected login can reduce time to detection.

In organizational terms, this incident is a reminder that default configurations or the reuse of cryptographic devices amplify the risk. Certificate management practices, asset inventory and periodic configuration tests (including job reviews such as override) should be part of vulnerability management programmes. Plot and workflow management tools that prioritize active operating CVE are essential to reduce the exposure window.

For teams that manage GlobalProtect applications, my final practical recommendation is not to assume that "there is no evidence of lateral movement" means that there is no risk: treating each detection as a potential commitment, applying patches, changing committed certificates, auditing administrative access and, if appropriate, notifying customers and regulators according to incident policies. The Palo Alto page with the indications and patches is the technical starting point to be consulted immediately: Palo Alto Networks page on CVE-2026-0257.

Coverage

Related

More news on the same subject.