Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
New Phishing-as-a-Service Kits Bypass MFA to Steal Microsoft 365 Logins
August 5, 2026
Critical TP-Link Omada ZTP Flaws Let Attackers Hijack Routers, Execute Root Code
August 5, 2026
Critical OVSwrap Linux Vulnerability (CVE-2024-3094) Lets Attackers Gain Root
August 5, 2026
Home/CyberSecurity News/Critical Palo Alto Networks PAN-OS Auth Bypass CVE-2024-3400 Exploited
CyberSecurity News

Critical Palo Alto Networks PAN-OS Auth Bypass CVE-2024-3400 Exploited

Key Takeaways A critical authentication bypass vulnerability, CVE-2026-0257, affecting Palo Alto Networks PAN-OS and Prisma Access, is currently being actively exploited in the wild. The flaw allows...

Sarah simpson
Sarah simpson
May 30, 2026 3 Min Read
56 0

Key Takeaways

  • A critical authentication bypass vulnerability, CVE-2026-0257, affecting Palo Alto Networks PAN-OS and Prisma Access, is currently being actively exploited in the wild.
  • The flaw allows unauthenticated remote attackers to forge VPN session cookies, granting unauthorized access to GlobalProtect gateways.
  • The vulnerability arises when a non-default “authentication override” feature shares its encryption certificate with the HTTPS service, enabling attackers to forge valid session cookies.
  • Organizations must immediately apply vendor-provided patches or implement specified mitigations to prevent exploitation.

Palo Alto Networks GlobalProtect Vulnerability Under Active Exploitation

A severe authentication bypass vulnerability, tracked as CVE-2026-0257, impacting Palo Alto Networks’ PAN-OS and Prisma Access, has been confirmed as actively exploited. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this critical flaw to its Known Exploited Vulnerabilities (KEV) catalog on May 29, 2026, underscoring the immediate threat it poses.

Table Of Content

  • Key Takeaways
  • Palo Alto Networks GlobalProtect Vulnerability Under Active Exploitation
  • Technical Details of CVE-2026-0257
  • Observed Exploitation Campaigns
  • Indicators of Compromise
  • What You Should Do

Palo Alto Networks initially issued a security advisory on May 13, 2026, detailing how CVE-2026-0257 could allow a remote, unauthenticated attacker to craft fraudulent authentication override cookies. This grants them the ability to establish unauthorized VPN connections through the GlobalProtect gateway, bypassing standard authentication mechanisms entirely.

Technical Details of CVE-2026-0257

The vulnerability specifically targets the “authentication override” feature, a non-default setting designed to enhance user experience by issuing session cookies to authenticated GlobalProtect users. These cookies function similarly to bearer tokens, eliminating the need for users to re-authenticate during subsequent sessions.

The critical flaw manifests when the certificate employed for encrypting and decrypting these authentication override cookies is inadvertently shared with another service, such as the HTTPS service of the portal or gateway. Researchers discovered that the /usr/local/bin/gpsvc binary, responsible for the cookie decryption process, lacks signature verification. Consequently, any attacker capable of extracting the public key from the exposed HTTPS certificate can forge a legitimate authentication cookie, thereby achieving a complete bypass of the authentication system.

Observed Exploitation Campaigns

Rapid7 documented the earliest instances of exploitation on May 17, 2026. The initial wave of attacks originated from IP addresses hosted on Vultr. By May 18, Rapid7 observed suspicious cookie-based authentication attempts targeting local administrator accounts across multiple client environments. During these initial incursions, attackers used the machine name GP-CLIENT and a spoofed MAC address (aa:bb:cc:dd:ee:ff) to impersonate legitimate endpoints.

A second, distinct wave of exploitation was identified on May 21, 2026. This time, the attacks originated from IP addresses associated with the hosting provider Dromatics Systems, utilizing the machine name DESKTOP-GP01. In this subsequent wave, some victims reported full VPN IP assignments being granted post-cookie authentication, providing attackers direct access to internal network resources. The consistent use of the spoofed MAC address across both campaigns strongly suggests a single threat actor is responsible for these coordinated attacks. Notably, out of ten impacted MDR customers, eight experienced only authentication probes rather than full VPN session establishment.

Indicators of Compromise

Indicator Type
104.207.144.154 Threat actor source IP (Wave 1)
146.19.216.119 / .120 / .125 Threat actor source IPs (Wave 2)
aa:bb:cc:dd:ee:ff Spoofed MAC address (both waves)
GP-CLIENT Machine name, Linux auth, May 17
DESKTOP-GP01 Machine name, Windows auth, May 21

Note: IP addresses and domains are intentionally defanged to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

What You Should Do

Palo Alto Networks has released patches, and organizations are urged to take immediate action to mitigate the risk posed by CVE-2026-0257. While the vulnerability carries a medium CVSSv4 score, its active exploitation as an initial access vector on internet-facing VPN appliances elevates it to a critical priority for defenders.

  • Upgrade all affected PAN-OS and Prisma Access instances to the latest patched versions. Key fixed versions include PAN-OS 12.1.4-h6 / 12.1.7, PAN-OS 11.2.12, PAN-OS 11.1.15, and PAN-OS 10.2.18-h6. For Prisma Access, 11.2.0 requires 11.2.7-h13 or later, and 10.2.0 requires 10.2.10-h36 or later.
  • If not operationally essential, disable the authentication override feature entirely.
  • Generate and utilize a dedicated certificate solely for authentication override cookie encryption. This certificate must never be shared with the HTTPS service.
  • Actively hunt for the provided Indicators of Compromise (IOCs) across your VPN and GlobalProtect authentication logs.
  • Deploy available detection rules, such as “Suspicious Authentication – Palo Alto GlobalProtect Cookie Authentication to Local Admin Account,” for platforms like InsightIDR/MDR.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityThreatVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Critical VS Code Bug Lets Attackers Steal Source Code and Secrets

Next Post

Google Chrome Device-Bound Sessions Go GA to Prevent Account Takeovers

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
EtherRAT Spreads via Scheduled Tasks in Compromised Windows Domains
August 5, 2026
7-Zip Mark-of-the-Web Bypass Lets Malicious Files Evade Windows SmartScreen
August 5, 2026
Microsoft Defender Stops QNET Ransomware Attack in 128 Seconds
August 5, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us