Attackers Exploit Critical Palo Alto Networks Auth Bypass in Two Waves, Researchers Warn
Palo Alto Networks raised the severity of CVE-2026-0257 from medium to critical after Rapid7 observed active exploitation in two waves starting in mid-May. The flaw lets attackers bypass authentication on GlobalProtect VPNs using a single HTTP request.
Attackers are actively exploiting an authentication bypass vulnerability in Palo Alto Networks PAN-OS firewalls that the vendor initially rated as medium severity. The flaw, tracked as CVE-2026-0257, allows remote attackers to forge a valid authentication cookie and establish a VPN connection to an unpatched device. Rapid7 observed the first exploitation in a customer environment on May 17, followed by a second wave of activity on May 21.
Palo Alto Networks disclosed the defect on May 13, but raised its severity to critical after Rapid7 confirmed exploitation. The Cybersecurity and Infrastructure Security Agency added the vulnerability to its known exploited vulnerabilities catalog on May 24. The flaw affects GlobalProtect portal or gateway configurations where authentication override cookies are enabled.
Single HTTP Request Exploit Relies on Public TLS Certificate
Jake Knott, a security researcher at watchTowr, described the exploit as remarkably simple. Attackers need only the firewall's publicly available TLS certificate to forge a cookie. The entire attack is a single HTTP request. The vulnerability requires that the cookie encryption and decryption certificate be reused with another feature, potentially exposing the public key. Caitlin Condon, vice president of security research at VulnCheck, said it is difficult to estimate how many deployments meet those criteria, but Palo Alto Networks' large footprint means even uncommon configurations present significant attack surface.
- Palo Alto Networks discovered the vulnerability internally using frontier AI tools.
- Rapid7 reported seeing new victims roll in within an hour of each other during the second wave.
- Multiple threat clusters are exploiting the flaw, but no specific group has been attributed.
- Attackers are not establishing full VPN connections or moving laterally in many cases, focusing instead on opportunistic initial access.
Pattern of Underestimated Vulnerabilities Becoming Urgent
Douglas McKee, director of vulnerability intelligence at Rapid7, noted that attackers are purposefully weaponizing medium severity vulnerabilities, which are often lower priority for organizations. The escalated threat underscores how quickly a seemingly mild flaw can turn into an urgent warning. "Organizations that wait for confirmation of active exploitation before patching will consistently find themselves reacting too late," Knott said. Palo Alto Networks urged all customers to apply patches or follow mitigation steps immediately.
The company is actively monitoring limited exploitation attempts on unpatched devices where mitigations have not been applied. Rapid7 said the same attacker or group is likely responsible for both waves. The long term objectives remain unclear, as the activity appears focused purely on opportunistic initial access rather than targeted espionage. Researchers continue to track new victims as the exploit code spreads across threat clusters.
Fact check
-
CVE-2026-0257 allows remote attackers to forge a valid authentication cookie using the firewall's publicly available TLS certificate.
reported · source
-
Rapid7 observed exploitation in two waves: first on May 17, second on May 21.
verified · source
-
CISA added the vulnerability to its known exploited vulnerabilities catalog on May 24.
reported · source
-
Palo Alto Networks discovered the vulnerability internally using frontier AI tools.
reported · source
Source reporting (3)
Related Articles
Snowflake hacker pleads guilty to stealing data from 165 organizations, faces 32 years in prison
Aug 5, 2026
AI Agents From OpenAI and Anthropic Breach Real Websites During Security Tests
Aug 5, 2026
AI Agent Security Startups Zenity and Horizon3.ai Raise $375M Combined as SentinelOne Expands Autonomous SOC
Aug 3, 2026
0 Comments
No comments yet
Be the first to share your thoughts on this article.