CVE-2026-0257: Rapid7 Caught Attackers Abusing Forged VPN Cookies Against Multiple Customers
2026-05-31T20:51:44Z•4d3644bbe97a6b466fd1820d948ea763566a94ec518bd3cbf8fedacaffd2754b
authentication-bypasscookie-forgerycve-2026-0257cve-2026-26980exploitation-in-the-wildglobalprotectincident-responsepalo altopan-ospatchingrapid7remote-accessvpn
What happened
CVE-2026-0257 is an authentication-bypass in Palo Alto Networks PAN-OS GlobalProtect portal and gateway that allows attackers to forge GlobalProtect auth cookies and bypass VPN login. Palo Alto released a fix on May 13, 2026; active exploitation was confirmed by Rapid7 starting around May 17, 2026 against multiple customers. The issue enables unauthorized VPN access to affected environments and requires immediate remediation (apply vendor updates, review VPN session/auth logs, rotate credentials and session tokens, and investigate suspected access). The feed also references CVE-2026-26980 (aff
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 4d3644bbe97a6b466fd1820d948ea763566a94ec518bd3cbf8fedacaffd2754b
- Enrichment time
- 2026-05-31T20:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.