Source: Attackers exploit Palo Alto GlobalProtect flaw days after disclosure | CSO Online
Author: unknown
URL: https://www.csoonline.com/article/4179847/attackers-exploit-palo-alto-globalprotect-flaw-days-after-disclosure.html
ONE SENTENCE SUMMARY:
Attackers exploit CVE-2026-0257 in Palo Alto GlobalProtect, bypassing authentication via forged cookies, accelerating patch urgency and zero-trust scrutiny.
MAIN POINTS:
- Active in-the-wild exploitation followed Palo Alto’s initial medium-severity disclosure within days.
- Rapid7 observed successful VPN access across customers, without confirmed lateral movement.
- CVE-2026-0257 impacts GlobalProtect remote-access VPN on PAN-OS devices.
- Exploitation reportedly began May 17, shortly after fixes and mitigations were published.
- Palo Alto raised CVSS to 7.8, marked “attacked,” and set highest urgency.
- Vulnerability enables credential-less authentication bypass by forging a trusted cookie.
- Sessions appear legitimate, complicating detection compared with typical intrusion methods.
- Root cause: decrypted cookie contents trusted without signature verification.
- Exposure requires specific configuration: override cookies enabled and shared certificate usage.
- CISA added it to KEV, ordering rapid remediation for federal agencies.
TAKEAWAYS:
- Treat auth-bypass flaws on remote-access gateways as critical, regardless of base scoring.
- Audit GlobalProtect configurations for authentication override cookies and certificate reuse.
- Patch immediately and apply mitigations; exploitation can start days after disclosure.
- Strengthen monitoring for suspicious “legitimate” VPN sessions that may be forged.
- Improve asset visibility and configuration governance to reduce edge-device exposure during zero-trust transitions.