CVE-2026-0257 Explained: The PAN-OS GlobalProtect Authentication Bypass
Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.
Enroll Now and Save 10%: Coupon Code MWNEWS10
Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.
Key Takeaways
- CVE-2026-0257 is a high-severity authentication bypass in PAN-OS GlobalProtect portal and gateway, actively exploited in the wild.
- A remote, unauthenticated attacker can forge a valid session cookie and establish an unauthorized VPN connection.
- The flaw stems from trusting decrypted cookies without integrity checks, combined with certificate reuse leaking the encryption key.
- A public proof-of-concept exists, harvesting public keys from TLS to forge cookies for privileged accounts like admin.
- The Picus Platform simulates CVE-2026-0257 attacks to test security control effectiveness against real-life exploitation.
CVE-2026-0257 is a high-severityauthentication bypass vulnerability in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS.
Article Link: CVE-2026-0257 Explained: The PAN-OS GlobalProtect Authentication Bypass
1 post - 1 participant
Malware Analysis, News and Indicators - Latest topics