Last Updated: 2026-05-31T10:30:00Z
What’s Happening
Reported exploitation of the authentication bypass vulnerability CVE-2026-0257 in PAN-OS GlobalProtect, allowing attackers to establish an unauthorized VPN connections.
Details of the vulnerability were first published on 2026-05-13. Rapid7’s earliest observed exploitation occurred on 2026-05-17. On 2026-05-29 the vulnerability was marked as known exploited and a public proof-of-concept was published.
Actions
-
Inventory existing PAN-OS GlobalProtect systems and consider the required configurations for exposure
-
When using a vulnerable configuration consider an assumed breach scenario looking back to at least 2026-05-17.
-
Update to a supported fixed version or apply one of the mitigations
a. Mitigation: Use a dedicated certificate for Authentication Override cookies
b. Mitigation: Disable Authentication Override
Indicators of Compromise
| Item | Description |
|---|---|
104.207.144.154 |
Threat actor source IP (reported by Rapid7) |
146.19.216.119 |
Threat actor source IP (reported by Rapid7) |
146.19.216.120 |
Threat actor source IP (reported by Rapid7) |
146.19.216.125 |
Threat actor source IP (reported by Rapid7) |
DESKTOP-GP01 |
Machinename observed in the GlobalProtect logs alongside Windows authentications first observed on May 21, 2026 (reported by Rapid7) |
GP-CLIENT |
Machinename observed in the GlobalProtect logs alongside Linux authentications first observed on May 17, 2026 (reported by Rapid7) |
aa:bb:cc:dd:ee:ff |
Spoofed MAC address observed in both waves of successful exploitation (reported by Rapid7) |
References
- Vendor advisory: CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
- Rapid7’s MDR report: Rapid7 Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257)
- Rapid7’s Stephen Fewer Proof-of-Concept:
https://github.com/sfewer-r7/CVE-2026-0257