CVE-2026-0257: PAN-OS GlobalProtect Authentication Bypass EITW

Last Updated: 2026-05-31T10:30:00Z

What’s Happening

Reported exploitation of the authentication bypass vulnerability CVE-2026-0257 in PAN-OS GlobalProtect, allowing attackers to establish an unauthorized VPN connections.

Details of the vulnerability were first published on 2026-05-13. Rapid7’s earliest observed exploitation occurred on 2026-05-17. On 2026-05-29 the vulnerability was marked as known exploited and a public proof-of-concept was published.

Actions

  1. Inventory existing PAN-OS GlobalProtect systems and consider the required configurations for exposure

  2. When using a vulnerable configuration consider an assumed breach scenario looking back to at least 2026-05-17.

  3. Update to a supported fixed version or apply one of the mitigations
    a. Mitigation: Use a dedicated certificate for Authentication Override cookies
    b. Mitigation: Disable Authentication Override

Indicators of Compromise

Item Description
104.207.144.154 Threat actor source IP (reported by Rapid7)
146.19.216.119 Threat actor source IP (reported by Rapid7)
146.19.216.120 Threat actor source IP (reported by Rapid7)
146.19.216.125 Threat actor source IP (reported by Rapid7)
DESKTOP-GP01 Machinename observed in the GlobalProtect logs alongside Windows authentications first observed on May 21, 2026 (reported by Rapid7)
GP-CLIENT Machinename observed in the GlobalProtect logs alongside Linux authentications first observed on May 17, 2026 (reported by Rapid7)
aa:bb:cc:dd:ee:ff Spoofed MAC address observed in both waves of successful exploitation (reported by Rapid7)

References

Great work on this writeup! Thank you for the detail and the formatting!

1 Like

Both Palo Alto and Rapid7 updated their blogposts on the 2nd and 3rd of June. Palo Alto added a FAQ section, Rapid7 added new indicators.

Rapid7 observed POST requests to /ssl-vpn/hipreport.esp and /ssl-vpn/getconfig.esp in the cases where a VPN tunnel was successfully established. The first submits security profile information and the second to establish the secure tunnel.

Item Description
209.99.191.137 Threat actor source IP (reported by Rapid7 on 2026-06-02)
79.130.26.202 Threat actor source IP (reported by Rapid7 on 2026-06-02)
Jocker Machinename observed alongside 79.130.26.202 (reported by Rapid7 on 2026-06-02)
2 Likes