Palo Alto GlobalProtect Auth Bypass Hits Live Exploitation

CVE-2026-0257 lets attackers stand up unauthorized VPN sessions against PAN-OS and Prisma Access. Patches are out. So are the exploits.

ThreatVectr Newsdesk· 2 min read
Palo Alto GlobalProtect Auth Bypass Hits Live Exploitation
Share

Palo Alto Networks is telling customers that a recently patched authentication bypass in PAN-OS and Prisma Access is being exploited in the wild.

The bug is tracked as CVE-2026-0257 and carries a CVSS score of 7.8. The vendor rates it medium severity. Attackers see it differently.

The flaw sits in the GlobalProtect authentication path. A successful exploit lets an unauthenticated attacker negotiate a VPN session against a vulnerable gateway or portal — effectively walking past the front door of the corporate network. From there, the usual playbook applies: reconnaissance, credential harvesting, lateral movement.

Palo Alto has not named victims or attributed the activity to a specific crew. The company's advisory simply notes "reports of active exploitation" and urges customers to patch immediately.

That language matters. Edge appliances from Palo Alto, Ivanti, Fortinet and Citrix have spent the last two years as the preferred entry point for ransomware affiliates and access brokers, who flip footholds on underground forums for four- and five-figure sums. GlobalProtect portals are internet-facing by design, which makes mass scanning trivial. Shodan-style enumeration of exposed PAN-OS instances typically returns tens of thousands of hits.

The bug affects PAN-OS deployments running GlobalProtect, and Prisma Access tenants where the gateway component is enabled. Hardware firewalls, virtualized NGFWs and cloud-delivered instances are all in scope depending on version. Palo Alto's security advisory lists the fixed builds.

For defenders, the patch is the priority. Where immediate patching isn't possible, the vendor's workaround guidance involves disabling GlobalProtect on affected interfaces — a non-starter for most enterprises that rely on it for remote access, but viable for isolated portals.

Hunting guidance is thinner. Authentication bypass exploitation tends to leave minimal forensic residue on the appliance itself. Teams should pull GlobalProtect authentication logs and look for successful session establishment without a corresponding successful auth event, anomalous source ASNs, and VPN clients connecting from geographies inconsistent with the user base. Egress traffic from gateway management interfaces is another tell.

The disclosure follows a familiar pattern for the vendor. Earlier flaws in PAN-OS, including the 2024 GlobalProtect command injection bug CVE-2024-3400, were similarly downgraded in initial severity before mass exploitation reframed the risk. That bug ultimately drew CISA emergency directive attention and was tied to state-aligned activity.

No Known Exploited Vulnerabilities Catalog entry for CVE-2026-0257 at time of writing. Expect that to change within the week.

No ransom demands, no leak-site posts, no named victims yet. The clock is on the defenders.

© 2026 Threat Vectr