NEWS Password? No, I haven't heard. How Hackers bypass Palo Alto Networks Protection with a Regular Cookie Session

Gold Surfer

Administrator
Staff member
Administrator
Moon-Club
Exclusive
Infinity
Premium
Member
Joined
Jan 20, 2026
Messages
345
Reaction score
2,425
Rapid7 recorded real cases of hacking of networks through a hole in GlobalProtect.
1780238858315.png
Palo Alto Networks has warned of attempts to exploit the vulnerability CVE-2026-0257 in PAN-OS and Prisma Access. The error affects GlobalProtect and with a certain configuration allows the attacker to bypass the authentication and install an unauthorized VPN connection.

The vulnerability was scored by 7.8 CVSS. The problem is in the portal and the freelance GlobalProtect, which use organizations to remotely access the internal network. If the attack is successful, an external intruder can connect to a VPN without a normal check of the account.

Not all devices with PAN-OS are vulnerable. The risk appears on firewalls, where the portal or the GlobalProtect gateway is configured, the function of skipping re-authentication through cookies is enabled and a certain certificate configuration is used at the same time. It is this combination of settings that opens the way to bypass protection.

Palo Alto Networks published a notice on May 13, 2026, and updated it on May 29 after operating reports. The company said it was aware of limited attempts to attack PAN-OS devices, where administrators did not apply temporary protection measures.

Separate details were revealed by Rapid7. The company found successful attacks on several customers. The earliest attempts date back to May 17, 2026, and the second wave began on May 21. According to Rapid7, both series are probably associated with the same attacker.

In the second wave of attacks, Rapid7 recorded two cases when, after authentication, a VPN address was assigned to the device through cookies. This gave the violator access to the internal network. At the same time, in those environments where the VPN session was established, experts did not see further actions of the attacker.

The danger of CVE-2026-0257 is not associated with the launch of the code on the device, but with the position of GlobalProtect on the perimeter of the network. A VPN gateway usually stands at the entrance to the corporate infrastructure. If an external person passes through it without a normal check, the organization receives the risk of unauthorized access to internal resources.

Rapid7 urged administrators to urgently establish patches from Palo Alto Networks. This type of vulnerability is particularly unpleasant for companies where remote access is constantly used: even limited operation can quickly turn into a serious incident if the attacker gains entrenches inside the network or access sensitive systems.

Before installing updates, Palo Alto Networks recommends temporary measures. Administrators can disable the re-authentication option through cookies or release a new certificate that will only be used for that function. Such steps should remove the dangerous configuration until the device is updated.

The story of CVE-2026-0257 fits into the broader trend of attacks on corporate remote access and management tools. Almost simultaneously, Arctic Wolf reported on the continued operation of the already corrected critical vulnerability of CVE-2026-35616 in the FortiClient Endpoint Management Server. Through it, the attackers distributed EKZ Infostealer, a malware for stealing accounts.

What is the conclusion? Devices on the perimeter need to be updated faster than conventional internal systems. VPN gateways, access portals, and management servers are the first to accept external traffic, so even a medium or high score error on the CVSS scale can be a convenient entry into the corporate network.
 

darkwebmoonforum

Member
Member
Joined
Jul 20, 2026
Messages
15
Reaction score
1
Rapid7 recorded real cases of hacking of networks through a hole in GlobalProtect.
View attachment 259
Palo Alto Networks has warned of attempts to exploit the vulnerability CVE-2026-0257 in PAN-OS and Prisma Access. The error affects GlobalProtect and with a certain configuration allows the attacker to bypass the authentication and install an unauthorized VPN connection.

The vulnerability was scored by 7.8 CVSS. The problem is in the portal and the freelance GlobalProtect, which use organizations to remotely access the internal network. If the attack is successful, an external intruder can connect to a VPN without a normal check of the account.

Not all devices with PAN-OS are vulnerable. The risk appears on firewalls, where the portal or the GlobalProtect gateway is configured, the function of skipping re-authentication through cookies is enabled and a certain certificate configuration is used at the same time. It is this combination of settings that opens the way to bypass protection.

Palo Alto Networks published a notice on May 13, 2026, and updated it on May 29 after operating reports. The company said it was aware of limited attempts to attack PAN-OS devices, where administrators did not apply temporary protection measures.

Separate details were revealed by Rapid7. The company found successful attacks on several customers. The earliest attempts date back to May 17, 2026, and the second wave began on May 21. According to Rapid7, both series are probably associated with the same attacker.

In the second wave of attacks, Rapid7 recorded two cases when, after authentication, a VPN address was assigned to the device through cookies. This gave the violator access to the internal network. At the same time, in those environments where the VPN session was established, experts did not see further actions of the attacker.

The danger of CVE-2026-0257 is not associated with the launch of the code on the device, but with the position of GlobalProtect on the perimeter of the network. A VPN gateway usually stands at the entrance to the corporate infrastructure. If an external person passes through it without a normal check, the organization receives the risk of unauthorized access to internal resources.

Rapid7 urged administrators to urgently establish patches from Palo Alto Networks. This type of vulnerability is particularly unpleasant for companies where remote access is constantly used: even limited operation can quickly turn into a serious incident if the attacker gains entrenches inside the network or access sensitive systems.

Before installing updates, Palo Alto Networks recommends temporary measures. Administrators can disable the re-authentication option through cookies or release a new certificate that will only be used for that function. Such steps should remove the dangerous configuration until the device is updated.

The story of CVE-2026-0257 fits into the broader trend of attacks on corporate remote access and management tools. Almost simultaneously, Arctic Wolf reported on the continued operation of the already corrected critical vulnerability of CVE-2026-35616 in the FortiClient Endpoint Management Server. Through it, the attackers distributed EKZ Infostealer, a malware for stealing accounts.

What is the conclusion? Devices on the perimeter need to be updated faster than conventional internal systems. VPN gateways, access portals, and management servers are the first to accept external traffic, so even a medium or high score error on the CVSS scale can be a convenient entry into the corporate network.
 

DARKWEB16 layers

Well-known member
Member
Joined
Aug 5, 2026
Messages
161
Reaction score
0
Rapid7 recorded real cases of hacking of networks through a hole in GlobalProtect.
View attachment 259
Palo Alto Networks has warned of attempts to exploit the vulnerability CVE-2026-0257 in PAN-OS and Prisma Access. The error affects GlobalProtect and with a certain configuration allows the attacker to bypass the authentication and install an unauthorized VPN connection.

The vulnerability was scored by 7.8 CVSS. The problem is in the portal and the freelance GlobalProtect, which use organizations to remotely access the internal network. If the attack is successful, an external intruder can connect to a VPN without a normal check of the account.

Not all devices with PAN-OS are vulnerable. The risk appears on firewalls, where the portal or the GlobalProtect gateway is configured, the function of skipping re-authentication through cookies is enabled and a certain certificate configuration is used at the same time. It is this combination of settings that opens the way to bypass protection.

Palo Alto Networks published a notice on May 13, 2026, and updated it on May 29 after operating reports. The company said it was aware of limited attempts to attack PAN-OS devices, where administrators did not apply temporary protection measures.

Separate details were revealed by Rapid7. The company found successful attacks on several customers. The earliest attempts date back to May 17, 2026, and the second wave began on May 21. According to Rapid7, both series are probably associated with the same attacker.

In the second wave of attacks, Rapid7 recorded two cases when, after authentication, a VPN address was assigned to the device through cookies. This gave the violator access to the internal network. At the same time, in those environments where the VPN session was established, experts did not see further actions of the attacker.

The danger of CVE-2026-0257 is not associated with the launch of the code on the device, but with the position of GlobalProtect on the perimeter of the network. A VPN gateway usually stands at the entrance to the corporate infrastructure. If an external person passes through it without a normal check, the organization receives the risk of unauthorized access to internal resources.

Rapid7 urged administrators to urgently establish patches from Palo Alto Networks. This type of vulnerability is particularly unpleasant for companies where remote access is constantly used: even limited operation can quickly turn into a serious incident if the attacker gains entrenches inside the network or access sensitive systems.

Before installing updates, Palo Alto Networks recommends temporary measures. Administrators can disable the re-authentication option through cookies or release a new certificate that will only be used for that function. Such steps should remove the dangerous configuration until the device is updated.

The story of CVE-2026-0257 fits into the broader trend of attacks on corporate remote access and management tools. Almost simultaneously, Arctic Wolf reported on the continued operation of the already corrected critical vulnerability of CVE-2026-35616 in the FortiClient Endpoint Management Server. Through it, the attackers distributed EKZ Infostealer, a malware for stealing accounts.

What is the conclusion? Devices on the perimeter need to be updated faster than conventional internal systems. VPN gateways, access portals, and management servers are the first to accept external traffic, so even a medium or high score error on the CVSS scale can be a convenient entry into the corporate network.
Telegram Join our Telegram channel! Welcome to our Telegram channel, blacks Join our Telegram channel, blacks room! Welcome to our Telegram channel, Blacks Room continues to grow! Welcome to our Telegram channel, Blacks Room continues to grow! 186 Welcome to our Telegram channel, Blacks Room! We continue to grow and have 186 members. Welcome to our Telegram channel, Blacks Room! We continue to grow, we have 186 members and entries are welcome. Welcome to our Telegram channel, Blacks Room! We're growing, we have 186 members, and entry is free. Welcome to our Telegram channel, Blacks Room! We continue to grow, we have 186 members and entry is free. Welcome to our Telegram channel, Blacks Room! We continue to grow, we have 186 members, and entry is free, but you need to send messages. Welcome to our Telegram channel, Blacks Room! We continue to grow, we have 186 members, and entry is free, but we have strict moderators for messaging. Welcome to our Telegram channel, Blacks Room! We continue to grow, we have 186 members, and entry is free, but we've implemented strict measures for sending messages. Welcome to our Telegram channel, Blacks Room! We continue to grow, we have 186 members, and entry is free, but we've implemented strict measures for sending messages. 35 35,000 35,000 Telegrams Pay 35,000 Telegram stars and then send a message. You can pay 35,000 Telegram stars and then send a message. You can pay 35,000 Telegram stars and then send a message. You can pay 35,000 Telegram stars and then send messages. This Telegram feature is only for legitimate sellers. You can pay 35,000 Telegram stars and then send messages. This Telegram is only for legitimate sellers. You can pay 35,000 Telegram stars and then send a message. This Telegram account is only for legitimate sellers and secure shopping. You can pay 35,000 Telegram stars and then send a message. This Telegram app is only for legitimate sellers and secure shopping. You can pay 35,000 Telegram stars and then send a message. This Telegram account is only for legitimate sellers and secure transactions. You can pay 35,000 Telegram stars and then send a message. This Telegram account is only for legitimate sellers and secure transactions. Now Now he's a scammer. No more scams We are putting an end to these scams now. We are putting an end to scams now, Blacks Room is safe. We are putting an end to scams; shop safely at Blacks Room. We are putting an end to scams; Blacks Room allows you to shop safely. We are putting an end to scams; Blacks Room allows you to shop safely.

 

DARKWRB3858484

Well-known member
Member
Joined
Aug 5, 2026
Messages
358
Reaction score
42
Rapid7 recorded real cases of hacking of networks through a hole in GlobalProtect.
View attachment 259
Palo Alto Networks has warned of attempts to exploit the vulnerability CVE-2026-0257 in PAN-OS and Prisma Access. The error affects GlobalProtect and with a certain configuration allows the attacker to bypass the authentication and install an unauthorized VPN connection.

The vulnerability was scored by 7.8 CVSS. The problem is in the portal and the freelance GlobalProtect, which use organizations to remotely access the internal network. If the attack is successful, an external intruder can connect to a VPN without a normal check of the account.

Not all devices with PAN-OS are vulnerable. The risk appears on firewalls, where the portal or the GlobalProtect gateway is configured, the function of skipping re-authentication through cookies is enabled and a certain certificate configuration is used at the same time. It is this combination of settings that opens the way to bypass protection.

Palo Alto Networks published a notice on May 13, 2026, and updated it on May 29 after operating reports. The company said it was aware of limited attempts to attack PAN-OS devices, where administrators did not apply temporary protection measures.

Separate details were revealed by Rapid7. The company found successful attacks on several customers. The earliest attempts date back to May 17, 2026, and the second wave began on May 21. According to Rapid7, both series are probably associated with the same attacker.

In the second wave of attacks, Rapid7 recorded two cases when, after authentication, a VPN address was assigned to the device through cookies. This gave the violator access to the internal network. At the same time, in those environments where the VPN session was established, experts did not see further actions of the attacker.

The danger of CVE-2026-0257 is not associated with the launch of the code on the device, but with the position of GlobalProtect on the perimeter of the network. A VPN gateway usually stands at the entrance to the corporate infrastructure. If an external person passes through it without a normal check, the organization receives the risk of unauthorized access to internal resources.

Rapid7 urged administrators to urgently establish patches from Palo Alto Networks. This type of vulnerability is particularly unpleasant for companies where remote access is constantly used: even limited operation can quickly turn into a serious incident if the attacker gains entrenches inside the network or access sensitive systems.

Before installing updates, Palo Alto Networks recommends temporary measures. Administrators can disable the re-authentication option through cookies or release a new certificate that will only be used for that function. Such steps should remove the dangerous configuration until the device is updated.

The story of CVE-2026-0257 fits into the broader trend of attacks on corporate remote access and management tools. Almost simultaneously, Arctic Wolf reported on the continued operation of the already corrected critical vulnerability of CVE-2026-35616 in the FortiClient Endpoint Management Server. Through it, the attackers distributed EKZ Infostealer, a malware for stealing accounts.

What is the conclusion? Devices on the perimeter need to be updated faster than conventional internal systems. VPN gateways, access portals, and management servers are the first to accept external traffic, so even a medium or high score error on the CVSS scale can be a convenient entry into the corporate network.
 
6,044Threads
80,020Messages
5,936Members
jack forLatest member
Top Bottom