Palo Alto Networks GlobalProtect VPN Auth Bypass Actively Exploited — CISA Urges Immediate Patching
Palo Alto Networks has confirmed that CVE-2026-0257, a medium-severity authentication bypass vulnerability in PAN-OS GlobalProtect portal and gateway, is under active exploitation in the wild. The vulnerability carries a CVSS score of 7.8 and allows an unauthenticated remote attacker to bypass security restrictions and establish unauthorized VPN connections into corporate networks.
The exploit is remarkably simple — described by security researchers as a single HTTP request — but requires specific conditions: the target must have GlobalProtect configured with authentication override cookies enabled. Despite the prerequisites, the ease of exploitation and the criticality of VPN access have made this a high-priority target.
CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog with a federal remediation deadline of June 4, 2026 — just days after disclosure. The rapid timeline reflects the severity of active exploitation.
This vulnerability emerges alongside reports that over 40,000 servers have been compromised in ongoing cPanel exploitation campaigns, and that Trend Micro's Apex One platform (CVE-2026-34926) was also detected during active exploitation. The FBI has separately warned about the Silent Ransom Group targeting enterprise infrastructure.
For organizations running Palo Alto firewalls with GlobalProtect enabled, the remediation is straightforward: apply the latest PAN-OS hotfix immediately and disable authentication override cookies if not strictly required. Panorama and Cloud NGFW deployments are not affected.
A single HTTP request to bypass VPN authentication is the kind of vulnerability that gets ransomware groups through the front door. With CISA's unusually tight remediation deadline, this is a patch-today situation for any organization exposing GlobalProtect to the internet.
How do I know if my Palo Alto firewall is affected?
You are affected if you run PAN-OS with GlobalProtect portal or gateway configured and authentication override cookies enabled. Panorama and Cloud NGFW are not impacted. Check your PAN-OS version against the advisory and apply the available hotfix.
What is CISA's remediation deadline?
Federal agencies must remediate CVE-2026-0257 by June 4, 2026. Private organizations should treat it with equal urgency given active exploitation.