Critical Palo Alto Networks PAN-OS Auth Bypass CVE-2024-3400 Exploited
Key Takeaways A critical authentication bypass vulnerability, CVE-2026-0257, affecting Palo Alto Networks PAN-OS and Prisma Access, is currently being actively exploited in the wild. The flaw allows...
Key Takeaways
- A critical authentication bypass vulnerability, CVE-2026-0257, affecting Palo Alto Networks PAN-OS and Prisma Access, is currently being actively exploited in the wild.
- The flaw allows unauthenticated remote attackers to forge VPN session cookies, granting unauthorized access to GlobalProtect gateways.
- The vulnerability arises when a non-default “authentication override” feature shares its encryption certificate with the HTTPS service, enabling attackers to forge valid session cookies.
- Organizations must immediately apply vendor-provided patches or implement specified mitigations to prevent exploitation.
Palo Alto Networks GlobalProtect Vulnerability Under Active Exploitation
A severe authentication bypass vulnerability, tracked as CVE-2026-0257, impacting Palo Alto Networks’ PAN-OS and Prisma Access, has been confirmed as actively exploited. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this critical flaw to its Known Exploited Vulnerabilities (KEV) catalog on May 29, 2026, underscoring the immediate threat it poses.
Table Of Content
Palo Alto Networks initially issued a security advisory on May 13, 2026, detailing how CVE-2026-0257 could allow a remote, unauthenticated attacker to craft fraudulent authentication override cookies. This grants them the ability to establish unauthorized VPN connections through the GlobalProtect gateway, bypassing standard authentication mechanisms entirely.
Technical Details of CVE-2026-0257
The vulnerability specifically targets the “authentication override” feature, a non-default setting designed to enhance user experience by issuing session cookies to authenticated GlobalProtect users. These cookies function similarly to bearer tokens, eliminating the need for users to re-authenticate during subsequent sessions.
The critical flaw manifests when the certificate employed for encrypting and decrypting these authentication override cookies is inadvertently shared with another service, such as the HTTPS service of the portal or gateway. Researchers discovered that the /usr/local/bin/gpsvc binary, responsible for the cookie decryption process, lacks signature verification. Consequently, any attacker capable of extracting the public key from the exposed HTTPS certificate can forge a legitimate authentication cookie, thereby achieving a complete bypass of the authentication system.
Observed Exploitation Campaigns
Rapid7 documented the earliest instances of exploitation on May 17, 2026. The initial wave of attacks originated from IP addresses hosted on Vultr. By May 18, Rapid7 observed suspicious cookie-based authentication attempts targeting local administrator accounts across multiple client environments. During these initial incursions, attackers used the machine name GP-CLIENT and a spoofed MAC address (aa:bb:cc:dd:ee:ff) to impersonate legitimate endpoints.
A second, distinct wave of exploitation was identified on May 21, 2026. This time, the attacks originated from IP addresses associated with the hosting provider Dromatics Systems, utilizing the machine name DESKTOP-GP01. In this subsequent wave, some victims reported full VPN IP assignments being granted post-cookie authentication, providing attackers direct access to internal network resources. The consistent use of the spoofed MAC address across both campaigns strongly suggests a single threat actor is responsible for these coordinated attacks. Notably, out of ten impacted MDR customers, eight experienced only authentication probes rather than full VPN session establishment.
Indicators of Compromise
| Indicator | Type |
|---|---|
104.207.144.154 |
Threat actor source IP (Wave 1) |
146.19.216.119 / .120 / .125 |
Threat actor source IPs (Wave 2) |
aa:bb:cc:dd:ee:ff |
Spoofed MAC address (both waves) |
GP-CLIENT |
Machine name, Linux auth, May 17 |
DESKTOP-GP01 |
Machine name, Windows auth, May 21 |
Note: IP addresses and domains are intentionally defanged to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
What You Should Do
Palo Alto Networks has released patches, and organizations are urged to take immediate action to mitigate the risk posed by CVE-2026-0257. While the vulnerability carries a medium CVSSv4 score, its active exploitation as an initial access vector on internet-facing VPN appliances elevates it to a critical priority for defenders.
- Upgrade all affected PAN-OS and Prisma Access instances to the latest patched versions. Key fixed versions include PAN-OS 12.1.4-h6 / 12.1.7, PAN-OS 11.2.12, PAN-OS 11.1.15, and PAN-OS 10.2.18-h6. For Prisma Access, 11.2.0 requires 11.2.7-h13 or later, and 10.2.0 requires 10.2.10-h36 or later.
- If not operationally essential, disable the authentication override feature entirely.
- Generate and utilize a dedicated certificate solely for authentication override cookie encryption. This certificate must never be shared with the HTTPS service.
- Actively hunt for the provided Indicators of Compromise (IOCs) across your VPN and GlobalProtect authentication logs.
- Deploy available detection rules, such as “Suspicious Authentication – Palo Alto GlobalProtect Cookie Authentication to Local Admin Account,” for platforms like InsightIDR/MDR.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.