ReliaQuest reports active exploitation of CVE-2026-0257, an authentication-bypass flaw affecting PAN-OS GlobalProtect and Prisma Access.
The reported path to unauthorized VPN access depends on specific configuration settings, including enabled authentication override cookies and a certificate setting.
The report also notes that these connections may resemble routine remote work.
Which facilities are affected?
Palo Alto Networks announced the issue on May 13, 2026 and rated it as high severity, giving it the highest priority for addressing. Not all installations are affected. The issue affects those that have the setting for special cookies that can bypass authentication enabled, along with a specific digital certificate setting.
Affected versions include PAN-OS 12.1, 11.2, 11.1, and 10.2, as well as Prisma Access 11.2 and 10.2. Panorama and Cloud NGFW are not affected.
Palo Alto Networks recommends that administrators check the exact version they are using and install the appropriate update. It also asks that they disable the setting for these cookies where they are not needed. If they do need them, they should use a new certificate specifically for them — not a certificate used in a GlobalProtect login or access gateway or other service.
The update must be installed on all internal and external GlobalProtect entry points that create or accept these cookies. In Prisma Access environments that combine the service with on-premises systems, affected firewalls located on company premises must also be updated. If the upgrade is left unfinished, compatibility issues may arise. After the change, users will need to log in again.
What is recommended after the update?
ReliaQuest recommends terminating all active GlobalProtect connections after the upgrade and investigating any unexpected connections. For example, the device name "kali" may be a reason to check, but does not in itself prove a breach.
Installing the update may not remove access that the attackers gained before the patch. ReliaQuest estimates that exploitation attempts are likely to continue over the next three months as extortion groups and middlemen selling access seek out unpatched systems.
Top comments (0)