Critical Vulnerability in Palo Alto Global Protect Under Active Exploitation (CVE-2026-0257)
Executive Summary
On July 20th, 2026 it was reported by security researchers that Qilin Ransomware affiliates are actively exploiting CVE-2026-0257, a critical authentication bypass vulnerability affecting Palo Alto Networks Global Protect Portal.
The vulnerability was previously added to CISA’s Known Exploited Vulnerabilities (KEV) database on May 29th[JC1] . Tracked as CVE-2026-0257, the flaw can allow an unauthenticated attacker to establish unauthorized VPN sessions on vulnerable GlobalProtect deployments when certain configuration conditions are present.
The vulnerability was originally released by Palo Alto May 13th, 2026 as a medium severity vulnerability. However, given confirmed exploitation in the wild and weaponization by well-established ransomware operators, Beazley Security strongly recommends affected organizations patch immediately.
Affected Systems and Products
Mitigations and Workarounds
As active exploitation has been confirmed in the wild and Palo Alto have released fixes for this vulnerability, and affected organizations should apply patches as soon as possible. If immediately updating is not an option, risk can be temporarily reduced by the following mitigation steps:
- Disable Authentication Override within the GlobalProtect portal. Configuration steps are included within Palo Alto’s original advisory.
- Restricting access to GlobalProtect to trusted networks where operationally feasible until patches can be applied.
- If Authentication Override is required, use a dedicated certificate exclusively for signing Authentication Override cookies and ensure keys are securely stored and managed.
Additionally, CISA recommends either turning off the vulnerable technologies or restricting the VPN access to them only to trusted IP addresses. It is suggested to monitor VPN connection logs for suspicious authentication patterns and to consider implementing additional authentication methods outside of GlobalProtect.
Indicators of Compromise (IoCs)
On July 20th, Arctic Wolf reported multiple engagements in which Qilin ransomware affiliates exploited CVE-2026-0257 as the initial access vector. Following successful exploitation, the threat actors established GlobalProtect SSL VPN sessions from systems identifying themselves with the hostname “kali”. In the investigated intrusions, VPN sessions originated from the following IP addresses:
- 108.61.229[.]217
- 108.61.75[.]232
- 2.188.33[.]52
- 199.247.22[.]193
- 70.34.205[.]43
Arctic Wolf has made available and are updating this GitHub repository with additional IoCs related to the campaign.
Technical Details
Palo Alto suggests that the vulnerability came from an authentication bypass vulnerability in GlobalProtect which allows attackers to bypass security restrictions and establishunauthorized VPN connections. This vulnerability is being actively exploited in the wild by ransomware operaters, as reported by security researchers at Arctic Wolf.
To be exploited, specific conditions on the GlobalProtect portal must be met. First, the authentication override feature must be enabled. Then, an affected device would need to be configured in a way where the certificate used for the authentication override cookie mechanism is also used elsewhere, like the GlobalProtect portal or the gateway HTTPS service. If this is the case, threat actors may be able to derive the public key, enabling the crafting of malicious override cookies. A possible attack chain would resemble as follows:
- The attacker retrieves a public encryption certificate from the target’s GlobalProtect portal or gateway to forge an authentication override cookie
- The attacker uses the certificate to encrypt an arbitrary authentication bypass cookie
- The maliciously crafted bypass cookie is implicitly trusted by the device, allowing access
To check a device configuration, users can look under Network > GlobalProtect > Gateways > [Gateway/Portal Name] > Agent Tab > Authentication Override Cookie to see if the functionality is enabled.
Due to active exploitation in the wild, publicly available proof of concept exploit code, and potential for unauthorized access through the VPN gateway, Beazley Security strongly recommends affected organizations patch immediately.
How Beazley Security is Responding
Beazley Security is monitoring client perimeter devices through our Exposure Management Platform to identify impacted devices and support organizations in remediation of any issues found.
We are also conducting threat hunts across our MDR environment to detect potential exploitation attempts against our clients.
If you believe your organization may have been impacted by this attack campaign and need support, please contact our Incident Response team.
Sources
- https://nvd.nist.gov/vuln/detail/cve-2026-0257
- https://gbhackers.com/cisa-warns-palo-alto-networks-pan-os-vulnerability/
- https://www.theregister.com/cyber-crime/2026/06/01/palo-alto-vpn-bug-graduates-from-advisory-to-active-exploitation/5249114
- https://security.paloaltonetworks.com/CVE-2026-0257
- https://www.decryptiondigest.com/blog/cisa-patch-deadlines-june-2026-pan-os-defender-langflow
- https://www.rapid7.com/blog/post/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257/
- https://arcticwolf.com/resources/blog/exploitation-of-cve-2026-0257-leads-to-qilin-ransomware/
- https://github.com/rtkwlf/wolf-tools/tree/main/threat-intelligence/cookie-crumbles-qilin
Vous êtes au courant d'un incident qui a un impact sur votre secteur d'activité ? Faites-nous savoir :