Cloud Security Alliance
GlobalProtect VPN Vulnerability Exploitation Analysis
Pages
11
Time to read
15 mins
Language
English
Pages
11
Time to read
15 mins
Language
English
This technical report details a significant vulnerability identified as CVE-2026-0257 within Palo Alto Networks' GlobalProtect VPN system. The report describes how this cookie-forging issue allows unauthorized attackers to bypass security measures, establishing authenticated tunnel sessions within enterprise networks. It explains that the vulnerability arises from a configuration flaw where the same TLS certificate is used for both the HTTPS service and the cookie signing function, enabling attackers to forge valid authentication cookies. The report outlines the timeline of exploitation activities observed by Rapid7's Managed Detection and Response team, identifying two main waves of attacks beginning in May 2026, which targeted local administrator accounts. Additionally, it discusses the implications of this vulnerability on network security, emphasizing the need for organizations to implement patches or mitigate the risk by using dedicated certificates for cookie signing. The report concludes with an assessment of the scale of exposure across various PAN-OS versions and highlights the urgent need for remediation to prevent unauthorized access.