CVE-2026-0257: Rapid7 Caught Attackers Abusing Forged VPN Cookies Against Multiple Customers

2026-05-31T20:51:44Z4d3644bbe97a6b466fd1820d948ea763566a94ec518bd3cbf8fedacaffd2754b
authentication-bypasscookie-forgerycve-2026-0257cve-2026-26980exploitation-in-the-wildglobalprotectincident-responsepalo altopan-ospatchingrapid7remote-accessvpn

What happened

CVE-2026-0257 is an authentication-bypass in Palo Alto Networks PAN-OS GlobalProtect portal and gateway that allows attackers to forge GlobalProtect auth cookies and bypass VPN login. Palo Alto released a fix on May 13, 2026; active exploitation was confirmed by Rapid7 starting around May 17, 2026 against multiple customers. The issue enables unauthorized VPN access to affected environments and requires immediate remediation (apply vendor updates, review VPN session/auth logs, rotate credentials and session tokens, and investigate suspected access). The feed also references CVE-2026-26980 (aff

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
4d3644bbe97a6b466fd1820d948ea763566a94ec518bd3cbf8fedacaffd2754b
Enrichment time
2026-05-31T20:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.