Palo Alto GlobalProtect vulnerability exploited in the wild
A vulnerability in the Palo Alto Networks GlobalProtect portal and gateway has been added to CISA's Known Exploited Vulnerabilities catalog. Tracked as CVE-2026-0257 with a CVSS score of 7.8, it may allow an attacker to bypass security restrictions and establish an unauthorised VPN connection. The issue affects specific PAN-OS configurations where GlobalProtect portal or gateway authentication override cookies are enabled and a particular certificate configuration is present. Rapid7 reports observing multiple successful exploitation attempts across customer environments. Affected organisations should apply available patches or follow the vendor's mitigation guidance.
What this means for your organisation
The VPN is often the outermost door into internal systems, and by design it is exposed to the internet. An attacker who establishes a connection without valid authentication is inside the perimeter and can move on towards systems never built to withstand threats from within. Because the flaw is configuration-dependent, organisations must check their own settings, not just the version number.
Berigo recommends
- Determine whether your GlobalProtect setup uses the affected configuration, and apply the patches.
- Review VPN logs for the period and look for sessions lacking the expected authentication trail.
- Require multi-factor authentication on all remote access and limit what a VPN session can reach.
- Include exposed perimeter components in vulnerability management with short remediation deadlines.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch