CVE-2026-0257 Explained: The PAN-OS GlobalProtect Authentication Bypass

Introduction to Malware Binary Triage (IMBT) Course

Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.

CVE-2026-0257 Explained: The PAN-OS GlobalProtect Authentication Bypass

Key Takeaways

  • CVE-2026-0257 is a high-severity authentication bypass in PAN-OS GlobalProtect portal and gateway, actively exploited in the wild.
  • A remote, unauthenticated attacker can forge a valid session cookie and establish an unauthorized VPN connection.
  • The flaw stems from trusting decrypted cookies without integrity checks, combined with certificate reuse leaking the encryption key.
  • A public proof-of-concept exists, harvesting public keys from TLS to forge cookies for privileged accounts like admin.
  • The Picus Platform simulates CVE-2026-0257 attacks to test security control effectiveness against real-life exploitation.

CVE-2026-0257 is a high-severityauthentication bypass vulnerability in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS.

Article Link: CVE-2026-0257 Explained: The PAN-OS GlobalProtect Authentication Bypass

1 post - 1 participant

Read full topic



Malware Analysis, News and Indicators - Latest topics
Next Post Previous Post