- Joined
- Jan 20, 2026
- Messages
- 345
- Reaction score
- 2,425
Rapid7 recorded real cases of hacking of networks through a hole in GlobalProtect.

Palo Alto Networks has warned of attempts to exploit the vulnerability CVE-2026-0257 in PAN-OS and Prisma Access. The error affects GlobalProtect and with a certain configuration allows the attacker to bypass the authentication and install an unauthorized VPN connection.
The vulnerability was scored by 7.8 CVSS. The problem is in the portal and the freelance GlobalProtect, which use organizations to remotely access the internal network. If the attack is successful, an external intruder can connect to a VPN without a normal check of the account.
Not all devices with PAN-OS are vulnerable. The risk appears on firewalls, where the portal or the GlobalProtect gateway is configured, the function of skipping re-authentication through cookies is enabled and a certain certificate configuration is used at the same time. It is this combination of settings that opens the way to bypass protection.
Palo Alto Networks published a notice on May 13, 2026, and updated it on May 29 after operating reports. The company said it was aware of limited attempts to attack PAN-OS devices, where administrators did not apply temporary protection measures.
Separate details were revealed by Rapid7. The company found successful attacks on several customers. The earliest attempts date back to May 17, 2026, and the second wave began on May 21. According to Rapid7, both series are probably associated with the same attacker.
In the second wave of attacks, Rapid7 recorded two cases when, after authentication, a VPN address was assigned to the device through cookies. This gave the violator access to the internal network. At the same time, in those environments where the VPN session was established, experts did not see further actions of the attacker.
The danger of CVE-2026-0257 is not associated with the launch of the code on the device, but with the position of GlobalProtect on the perimeter of the network. A VPN gateway usually stands at the entrance to the corporate infrastructure. If an external person passes through it without a normal check, the organization receives the risk of unauthorized access to internal resources.
Rapid7 urged administrators to urgently establish patches from Palo Alto Networks. This type of vulnerability is particularly unpleasant for companies where remote access is constantly used: even limited operation can quickly turn into a serious incident if the attacker gains entrenches inside the network or access sensitive systems.
Before installing updates, Palo Alto Networks recommends temporary measures. Administrators can disable the re-authentication option through cookies or release a new certificate that will only be used for that function. Such steps should remove the dangerous configuration until the device is updated.
The story of CVE-2026-0257 fits into the broader trend of attacks on corporate remote access and management tools. Almost simultaneously, Arctic Wolf reported on the continued operation of the already corrected critical vulnerability of CVE-2026-35616 in the FortiClient Endpoint Management Server. Through it, the attackers distributed EKZ Infostealer, a malware for stealing accounts.
What is the conclusion? Devices on the perimeter need to be updated faster than conventional internal systems. VPN gateways, access portals, and management servers are the first to accept external traffic, so even a medium or high score error on the CVSS scale can be a convenient entry into the corporate network.

Palo Alto Networks has warned of attempts to exploit the vulnerability CVE-2026-0257 in PAN-OS and Prisma Access. The error affects GlobalProtect and with a certain configuration allows the attacker to bypass the authentication and install an unauthorized VPN connection.
The vulnerability was scored by 7.8 CVSS. The problem is in the portal and the freelance GlobalProtect, which use organizations to remotely access the internal network. If the attack is successful, an external intruder can connect to a VPN without a normal check of the account.
Not all devices with PAN-OS are vulnerable. The risk appears on firewalls, where the portal or the GlobalProtect gateway is configured, the function of skipping re-authentication through cookies is enabled and a certain certificate configuration is used at the same time. It is this combination of settings that opens the way to bypass protection.
Palo Alto Networks published a notice on May 13, 2026, and updated it on May 29 after operating reports. The company said it was aware of limited attempts to attack PAN-OS devices, where administrators did not apply temporary protection measures.
Separate details were revealed by Rapid7. The company found successful attacks on several customers. The earliest attempts date back to May 17, 2026, and the second wave began on May 21. According to Rapid7, both series are probably associated with the same attacker.
In the second wave of attacks, Rapid7 recorded two cases when, after authentication, a VPN address was assigned to the device through cookies. This gave the violator access to the internal network. At the same time, in those environments where the VPN session was established, experts did not see further actions of the attacker.
The danger of CVE-2026-0257 is not associated with the launch of the code on the device, but with the position of GlobalProtect on the perimeter of the network. A VPN gateway usually stands at the entrance to the corporate infrastructure. If an external person passes through it without a normal check, the organization receives the risk of unauthorized access to internal resources.
Rapid7 urged administrators to urgently establish patches from Palo Alto Networks. This type of vulnerability is particularly unpleasant for companies where remote access is constantly used: even limited operation can quickly turn into a serious incident if the attacker gains entrenches inside the network or access sensitive systems.
Before installing updates, Palo Alto Networks recommends temporary measures. Administrators can disable the re-authentication option through cookies or release a new certificate that will only be used for that function. Such steps should remove the dangerous configuration until the device is updated.
The story of CVE-2026-0257 fits into the broader trend of attacks on corporate remote access and management tools. Almost simultaneously, Arctic Wolf reported on the continued operation of the already corrected critical vulnerability of CVE-2026-35616 in the FortiClient Endpoint Management Server. Through it, the attackers distributed EKZ Infostealer, a malware for stealing accounts.
What is the conclusion? Devices on the perimeter need to be updated faster than conventional internal systems. VPN gateways, access portals, and management servers are the first to accept external traffic, so even a medium or high score error on the CVSS scale can be a convenient entry into the corporate network.