Critical Palo Alto GlobalProtect CVE-2024-3400 Exploited by Ransomware
Key Takeaways Ransomware groups, including Qilin and Settra, are actively exploiting CVE-2026-0257, a critical authentication bypass in Palo Alto Networks GlobalProtect and Prisma Access. The...
Key Takeaways
- Ransomware groups, including Qilin and Settra, are actively exploiting CVE-2026-0257, a critical authentication bypass in Palo Alto Networks GlobalProtect and Prisma Access.
- The vulnerability allows attackers to create unauthorized VPN sessions, bypassing security measures and gaining access to internal networks.
- The issue affects specific configurations of PAN-OS 12.1, 11.2, 11.1, and 10.2, as well as Prisma Access 11.2 and 10.2, when authentication override cookies are enabled with a particular certificate setup.
- Palo Alto Networks has released patches, and immediate upgrades, disabling unnecessary authentication override cookies, and generating new, dedicated certificates are crucial for mitigation.
Ransomware organizations are actively leveraging a severe authentication bypass, identified as CVE-2026-0257, impacting Palo Alto Networks’ GlobalProtect and Prisma Access solutions. Cybersecurity firm ReliaQuest has observed multiple threat actors, notably Qilin and Settra, exploiting this flaw to establish illicit VPN sessions. This grants them unauthorized entry into internal networks via trusted remote access services.
Table Of Content
This exploitation presents a significant challenge for detection, as the attackers’ network traffic often mimics legitimate remote work activity. This camouflage provides them ample time to exfiltrate credentials, navigate internal systems, gather sensitive data, or prepare ransomware deployment before security teams can identify the intrusion.
In a recent threat update, ReliaQuest also highlighted associated malicious activities involving tools like Cobalt Strike, BloodHound, and SharpHound. These observations underscore the necessity for defenders to meticulously investigate post-VPN connection activity, rather than assuming the legitimacy of a successful connection alone.
GlobalProtect Authentication Bypass Details
Palo Alto Networks officially disclosed CVE-2026-0257 on May 13, 2026. The vendor’s security advisory assigns a CVSS score of 7.8, classifying it as a High severity vulnerability with the highest recommended response urgency. The flaw allows an attacker to bypass authentication protocols and establish an unauthorized VPN connection without requiring valid credentials.
The susceptibility to this vulnerability is dependent on specific configurations. A GlobalProtect portal or gateway must have authentication override cookies enabled in conjunction with a particular certificate setup. While these cookies facilitate seamless authentication across GlobalProtect components, the vulnerability arises from an insufficient validation and integrity check mechanism for these cookies. Consequently, not all Palo Alto Networks deployments are exposed to this risk.
The advisory lists affected releases across PAN-OS versions 12.1, 11.2, 11.1, and 10.2, alongside Prisma Access versions 11.2 and 10.2. Notably, Panorama and Cloud NGFW products are not affected. Administrators are advised to cross-reference their exact maintenance release against the vendor’s detailed fixed version table, rather than relying solely on the primary version number.
Previous reports detailing Qilin’s exploitation of CVE-2026-0257 described a progression from unauthorized VPN access to credential theft and subsequent ransomware deployment. ReliaQuest’s latest findings, which now include Settra alongside Qilin, confirm that the exploitation of this vulnerability is not confined to a single ransomware operation.
What You Should Do
- Immediately upgrade all affected GlobalProtect and Prisma Access deployments to the patched versions specified in Palo Alto Networks’ security advisory.
- Disable authentication override cookies where they are not strictly necessary for operational functionality.
- Generate a new, dedicated certificate exclusively for authentication override cookies. Do not reuse existing portal, gateway, or other service certificates.
- Ensure that all internal and external GlobalProtect portals and gateways involved in generating or accepting authentication cookies are updated.
- For hybrid Prisma Access environments, extend upgrades to affected on-premises firewalls. Be aware that incomplete upgrades can lead to cookie compatibility issues.
- Terminate all active GlobalProtect sessions after applying patches, as pre-existing access may not be revoked automatically.
- Investigate any unexpected connections, particularly those originating from unusual hostnames such as “kali,” as these could indicate compromise.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.