Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Palo Alto GlobalProtect CVE-2024-3400 Exploited by Ransomware
October 11, 2026
Microsoft Teams to Warn Users of Malicious QR Code Links
October 10, 2026
Critical AWS Bug Exposes AI Agents to Credential Theft
October 10, 2026
Home/CyberSecurity News/Critical Palo Alto GlobalProtect CVE-2024-3400 Exploited by Ransomware
CyberSecurity News

Critical Palo Alto GlobalProtect CVE-2024-3400 Exploited by Ransomware

Key Takeaways Ransomware groups, including Qilin and Settra, are actively exploiting CVE-2026-0257, a critical authentication bypass in Palo Alto Networks GlobalProtect and Prisma Access. The...

Marcus Rodriguez
Marcus Rodriguez
October 11, 2026 3 Min Read
3 0

Key Takeaways

  • Ransomware groups, including Qilin and Settra, are actively exploiting CVE-2026-0257, a critical authentication bypass in Palo Alto Networks GlobalProtect and Prisma Access.
  • The vulnerability allows attackers to create unauthorized VPN sessions, bypassing security measures and gaining access to internal networks.
  • The issue affects specific configurations of PAN-OS 12.1, 11.2, 11.1, and 10.2, as well as Prisma Access 11.2 and 10.2, when authentication override cookies are enabled with a particular certificate setup.
  • Palo Alto Networks has released patches, and immediate upgrades, disabling unnecessary authentication override cookies, and generating new, dedicated certificates are crucial for mitigation.

Ransomware organizations are actively leveraging a severe authentication bypass, identified as CVE-2026-0257, impacting Palo Alto Networks’ GlobalProtect and Prisma Access solutions. Cybersecurity firm ReliaQuest has observed multiple threat actors, notably Qilin and Settra, exploiting this flaw to establish illicit VPN sessions. This grants them unauthorized entry into internal networks via trusted remote access services.

Table Of Content

  • Key Takeaways
  • GlobalProtect Authentication Bypass Details
  • What You Should Do

This exploitation presents a significant challenge for detection, as the attackers’ network traffic often mimics legitimate remote work activity. This camouflage provides them ample time to exfiltrate credentials, navigate internal systems, gather sensitive data, or prepare ransomware deployment before security teams can identify the intrusion.

In a recent threat update, ReliaQuest also highlighted associated malicious activities involving tools like Cobalt Strike, BloodHound, and SharpHound. These observations underscore the necessity for defenders to meticulously investigate post-VPN connection activity, rather than assuming the legitimacy of a successful connection alone.

GlobalProtect Authentication Bypass Details

Palo Alto Networks officially disclosed CVE-2026-0257 on May 13, 2026. The vendor’s security advisory assigns a CVSS score of 7.8, classifying it as a High severity vulnerability with the highest recommended response urgency. The flaw allows an attacker to bypass authentication protocols and establish an unauthorized VPN connection without requiring valid credentials.

The susceptibility to this vulnerability is dependent on specific configurations. A GlobalProtect portal or gateway must have authentication override cookies enabled in conjunction with a particular certificate setup. While these cookies facilitate seamless authentication across GlobalProtect components, the vulnerability arises from an insufficient validation and integrity check mechanism for these cookies. Consequently, not all Palo Alto Networks deployments are exposed to this risk.

The advisory lists affected releases across PAN-OS versions 12.1, 11.2, 11.1, and 10.2, alongside Prisma Access versions 11.2 and 10.2. Notably, Panorama and Cloud NGFW products are not affected. Administrators are advised to cross-reference their exact maintenance release against the vendor’s detailed fixed version table, rather than relying solely on the primary version number.

Previous reports detailing Qilin’s exploitation of CVE-2026-0257 described a progression from unauthorized VPN access to credential theft and subsequent ransomware deployment. ReliaQuest’s latest findings, which now include Settra alongside Qilin, confirm that the exploitation of this vulnerability is not confined to a single ransomware operation.

What You Should Do

  • Immediately upgrade all affected GlobalProtect and Prisma Access deployments to the patched versions specified in Palo Alto Networks’ security advisory.
  • Disable authentication override cookies where they are not strictly necessary for operational functionality.
  • Generate a new, dedicated certificate exclusively for authentication override cookies. Do not reuse existing portal, gateway, or other service certificates.
  • Ensure that all internal and external GlobalProtect portals and gateways involved in generating or accepting authentication cookies are updated.
  • For hybrid Prisma Access environments, extend upgrades to affected on-premises firewalls. Be aware that incomplete upgrades can lead to cookie compatibility issues.
  • Terminate all active GlobalProtect sessions after applying patches, as pre-existing access may not be revoked automatically.
  • Investigate any unexpected connections, particularly those originating from unusual hostnames such as “kali,” as these could indicate compromise.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchransomwareSecurityThreatVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Microsoft Teams to Warn Users of Malicious QR Code Links

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical AnyDesk Linux Flaw Lets Remote Attackers Execute Code as Root
October 9, 2026
GhostAction Attack Steals Secrets from GitHub Repositories
October 9, 2026
Critical Vulnerability in Terraform Exposes Developer Systems to Malware
October 9, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us