INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Palo Alto Auth Bypass Bug Exploit Under Active Threat
| 2026-06-01 08:30 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The threat landscape is rapidly evolving, with new vulnerabilities and exploits emerging daily. The recent incident involving China's TA4922 Expands Cybercrime Attacks Globally has highlighted the importance of staying vigilant against cyber threats. As organizations continue to upgrade their security technology in response to this vulnerability, it's essential for them to prioritize patching and mitigations to minimize the risk of successful attacks. With attackers exploiting vulnerabilities like authentication override in Palo Alto Networks' PAN-OS GlobalProtect VPN technology, timely updates are crucial to prevent lateral movement and data breaches.
Technical Mitigations AI-generated
* Configure GlobalProtect gateways to use a secure certificate that is not the same as the HTTPS service's certificate, and ensure certificates used for cookie encryption do not match those used for HTTPS services.
* Implement a secure authentication override configuration, where cookies issued by the portal or gateway are encrypted with a different certificate than those used for HTTPS services.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-0257CVE-2026-0257
CVE-2025-0108CVE-2025-0108
Target & Sectors
CN
CZ
Incident Timeline
May 18 and 21
Threat actors exploited the Palo Alto Auth Bypass Flaw in two waves, likely by the same actor, starting May 18 and 21.
2026/05/02
Threat actors are using a recently patched vulnerability in Palo Alto Auth to target vulnerable systems.
May 17
Threat actors exploited a vulnerability in Palo Alto Auth, identified by Rapid7 as early as May 17.
May 17, 2026
Threat actors exploited a Palo Alto Auth Bypass Flaw in attacks targeting systems as early as May 17, 2026.
May 18
Threat actors exploited a vulnerability in Palo Alto Auth's infrastructure to target Vultr on May 18.
Click on any entity below to view its context and source!
organisation
Vultr
The company first observed exploitation on May 18 from infrastructure hosted by Vultr, with a second wave of attacks detected on May 21 originating from Dromatics Systems.
organisation
Dromatics Systems
The company first observed exploitation on May 18 from infrastructure hosted by Vultr, with a second wave of attacks detected on May 21 originating from Dromatics Systems.
May 21
Threat actors used Vultr infrastructure to exploit a Palo Alto Auth Bypass Flaw on May 21.
Click on any entity below to view its context and source!
organisation
Vultr
The company first observed exploitation on May 18 from infrastructure hosted by Vultr, with a second wave of attacks detected on May 21 originating from Dromatics Systems.
organisation
Dromatics Systems
The company first observed exploitation on May 18 from infrastructure hosted by Vultr, with a second wave of attacks detected on May 21 originating from Dromatics Systems.
2026/05/25
Threat actors exploited the Palo Alto Auth Bypass Flaw in attacks that targeted unpatched devices without mitigations applied.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-0257
In May,
Palo Alto Networks
(PAN) disclosed and fixed the flaw, tracked as
CVE-2026-0257,
but it updated the advisory last week to note that there have been "limited exploit attempts on unpatched PAN-OS devices without mitigations applied.
organisation
Palo Alto Networks
In May,
Palo Alto Networks
(PAN) disclosed and fixed the flaw, tracked as
CVE-2026-0257,
but it updated the advisory last week to note that there have been "limited exploit attempts on unpatched PAN-OS devices without mitigations applied.
May 29
Threat actors exploited the Palo Alto Auth Bypass Flaw in May.
Click on any entity below to view its context and source!
attribution
Known Exploited
And on May 29, the Cybersecurity and Infrastructure Security Agency (CISA) also added the flaw to its Known Exploited Vulnerabilities (KEV) catalog.
tactic
T1588.006 - Vulnerabilities
And on May 29, the Cybersecurity and Infrastructure Security Agency (CISA) also added the flaw to its Known Exploited Vulnerabilities (KEV) catalog.
attribution
KEV
And on May 29, the Cybersecurity and Infrastructure Security Agency (CISA) also added the flaw to its Known Exploited Vulnerabilities (KEV) catalog.
May 29, 2026
Threat actors exploited a vulnerability in Palo Alto Auth Bypass to target systems.
June 1
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-0257 to its Known Exploited Vulnerabilities Catalog, requiring federal civilian agencies to patch it by June 1.
Click on any entity below to view its context and source!
source_region
United States
Store it securely, and don’t reuse or share it with other users
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) Catalog, requiring federal civilian agencies to patch it by June 1.
vulnerability
CVE-2026-0257
Store it securely, and don’t reuse or share it with other users
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) Catalog, requiring federal civilian agencies to patch it by June 1.
attribution
CVE-2026
Store it securely, and don’t reuse or share it with other users
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) Catalog, requiring federal civilian agencies to patch it by June 1.
attribution
Known Exploited
Store it securely, and don’t reuse or share it with other users
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) Catalog, requiring federal civilian agencies to patch it by June 1.
tactic
T1588.006 - Vulnerabilities
Store it securely, and don’t reuse or share it with other users
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) Catalog, requiring federal civilian agencies to patch it by June 1.
attribution
KEV
Store it securely, and don’t reuse or share it with other users
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) Catalog, requiring federal civilian agencies to patch it by June 1.
June 1, 2026
Threat actors exploited a known vulnerability in Palo Alto Auth.
Click on any entity below to view its context and source!
attribution
Known Exploited Vulnerability
CISA has now
added the flaw
to its Known Exploited Vulnerability catalog, ordering federal agencies to mitigate the flaw by June 1, 2026.
2026/06/01
Threat actors exploited a vulnerability in Palo Alto Auth Bypass Flaw Exploited in Attacks, specifically CVE-2026-0257 found in PAN-OS software.
Click on any entity below to view its context and source!
organisation
CVE-2026-0257
CVE-2026-0257 is an authentication bypass vulnerability in the GlobalProtect portal and gateway of Palo Alto Networks’ PAN-OS software.
In this case, it would be wise for customers affected by CVE-2026-0257 to apply PAN's fix as soon as possible, according to both PAN and Rapid7.
Palo Alto Networks is warning that hackers are now exploiting a PAN-OS GlobalProtect authentication bypass flaw, tracked as CVE-2026-0257, in attacks attempting to breach corporate networks.
organisation
GlobalProtect
CVE-2026-0257 is an authentication bypass vulnerability in the GlobalProtect portal and gateway of Palo Alto Networks’ PAN-OS software.
Palo Alto Networks is warning that hackers are now exploiting a PAN-OS GlobalProtect authentication bypass flaw, tracked as CVE-2026-0257, in attacks attempting to breach corporate networks.
The bug affects the GlobalProtect portal and gateway for the
PAN-OS software
across various versions, which are listed in the advisory.
organisation
PAN
CVE-2026-0257 is an authentication bypass vulnerability in the GlobalProtect portal and gateway of Palo Alto Networks’ PAN-OS software.
Palo Alto Networks is warning that hackers are now exploiting a PAN-OS GlobalProtect authentication bypass flaw, tracked as CVE-2026-0257, in attacks attempting to breach corporate networks.
Attackers are exploiting a security vulnerability in Palo Alto Networks' PAN-OS GlobalProtect VPN technology that allows them to bypass authentication and gain VPN access without valid credentials.
organisation
CVSS
The bug has a CVSS score of 7.8.
An internal researcher at the company discovered the flaw, which received an initial CVSS score of 7.8 that rated it of "medium" severity, since it requires firewalls with the GlobalProtect portal or gateway configured to have both authentication override cookies enabled and a specific certificate configuration.
organisation
IP
“Rapid7 observed VPN IP assignment following the cookie authentication, granting them access to the internal network.
organisation
MDR
“Across multiple customers, Rapid7 observed successful exploitation via authentication probes using forged cookies, but the appliance accepted the cookie without a full VPN session being established in 8 out of 10 impacted MDR customers.”
GlobalProtect VPN users are urged to patch immediately.
"Rapid7 MDR identified successful exploitation across numerous customers, however we did not observe any indication of successful lateral movement from the devices.
organisation
GlobalProtect VPN
“Across multiple customers, Rapid7 observed successful exploitation via authentication probes using forged cookies, but the appliance accepted the cookie without a full VPN session being established in 8 out of 10 impacted MDR customers.”
GlobalProtect VPN users are urged to patch immediately.
organisation
TA4922 Expands Cybercrime Attacks Globally
Related:
China's TA4922 Expands Cybercrime Attacks Globally
Denis Calderon, Suzu Labs CTO and principal, tells Dark Reading that the CVSSv4 score of 7.8 set the wrong tone from the start, though he doesn't disagree with the rating on principle.
organisation
Apply Cybersecurity Mitigations
Apply Cybersecurity Mitigations Now
Because its security technology stands in the way of attackers accessing the corporate network, security bugs in
Palo Alto Networks technology
often come under attack.
organisation
Palo Alto Networks
However, on Friday, Palo Alto Networks updated the advisory to warn that the flaw was now being actively exploited in attacks against unpatched devices, raising the severity rating to High.
organisation
Another Palo Alto Auth Bypass Bug Under
Patch Now: Another Palo Alto Auth Bypass Bug Under Active Exploit.
organisation
PoC
Related:
'The Com' Cyberattacks Support Violence & Sexploitation
Rapid7 developed a proof-of-concept (PoC) tool that successfully demonstrated the attack, showing that a forged cookie could be accepted by vulnerable GlobalProtect gateways and used to establish authenticated sessions.
Related:
State Cyber Leaders Push Congress for More Funding, Support
Rapid7 developed a proof-of-concept (PoC) tool that successfully demonstrated the attack, showing that a forged cookie could be accepted by vulnerable GlobalProtect gateways and used to establish authenticated sessions.
organisation
State
Related:
State Cyber Leaders Push Congress for More Funding, Support
Rapid7 developed a proof-of-concept (PoC) tool that successfully demonstrated the attack, showing that a forged cookie could be accepted by vulnerable GlobalProtect gateways and used to establish authenticated sessions.
organisation
PHP
Earlier this year, threat actors targeted
a separate authentication-bypass flaw
found in PAN-OS software that allows an unauthenticated attacker to invoke certain PHP scripts.
organisation
AI-Assisted Exploit Development Outpaces
Related:
AI-Assisted Exploit Development Outpaces Scanner Detection
How the PAN VPN Exploit Occurs
The issue lies in a feature called "authentication override," which allows a GlobalProtect portal or gateway to issue cookies to an authenticated user.
organisation
Palo Alto GlobalProtect VPN auth
Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks.
organisation
PAN-OS's
The researchers say the flaw stems from PAN-OS's validation of authentication override cookies.
organisation
HTTPS
If the same certificate is reused for both HTTPS services and authentication override cookies, attackers can obtain the corresponding public key via the HTTPS session and then use it to create forged cookies that the device will accept as legitimate.
Intelligence Sources
BleepingComputer
2026-05-30
Dark Reading
2026-06-01
Dark Reading
2026-06-01
Infosecurity-Magazine
2026-06-01
Palo Alto Warns High-Severity Bug Is Being Actively Exploited
Infosecurity-Magazine
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-10T10:30
Comprehensive Tactical Telemetry
Highly Correlated Entities
20x
organisation
Identified Entity
CVE-2026-0257
entity
11x
timeline
Temporal Reference
June 1
date
8x
attribution
Attributing Entity
The US Cybersecurity and Infrastructure Security Agency
authority
2x
vulnerability
Exploited CVE
CVE-2026-0257
cve
2x
target region
Target Country
China
country
2x
tactic
Cyber Operation Type
Lateral Movement
tactic
Contextual Telemetry
Context Block
7 METRICS
source region
Origin Country
United States
country
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
vulnerability
CVSS Score
8
score
malware
Malware Payload
Denis
tool
industry
Targeted Sector
Technology
sector
general metric
Cve-2026
257
cve-2026
general metric
Surfaces
6
surfaces
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.