Opens in a new tab

GlobalProtect Flaw Used for Stealthy VPN Access

Ransomware groups exploiting Palo Alto GlobalProtect auth bypass for covert VPN access

The GlobalProtect flaw tracked as CVE-2026-0257 is being exploited by ransomware actors to establish unauthorised VPN sessions. Because the connections pass through an organisation’s trusted remote access service, malicious activity can initially resemble legitimate remote work.

On 11 October 2026, Cyber Security News reported that ReliaQuest had observed actors associated with Qilin and Settra abusing the vulnerability. The report said attackers used their VPN access for post-exploitation activity involving Cobalt Strike, BloodHound and SharpHound, although the reviewed primary sources did not independently corroborate Settra’s involvement or that specific toolset attribution.

How the GlobalProtect flaw bypasses authentication

CVE-2026-0257 is a configuration-dependent authentication bypass affecting GlobalProtect portals and gateways in certain Palo Alto Networks PAN-OS and Prisma Access releases. Palo Alto Networks disclosed the vulnerability and published fixes on 13 May 2026, assigning it a High severity rating and a CVSS score of 7.8.

Exploitation requires authentication override cookies to be enabled and the relevant certificate configuration to be present. These cookies allow authentication to carry across GlobalProtect components, reducing the need for users to repeatedly sign in.

In affected configurations, certain PAN-OS versions can trust a cookie that they can decrypt with the configured certificate without adequately verifying that the device generated it under appropriate conditions. An unauthenticated attacker able to forge or misuse such a cookie may obtain a fully authenticated VPN session without valid credentials or completing multi-factor authentication.

Certificate reuse or exposure can increase the risk. For example, using the same certificate for authentication override and another portal, gateway or service may provide conditions that an attacker can exploit. The GlobalProtect flaw does not therefore affect every deployment running a listed software branch.

Why the VPN sessions are difficult to detect

Once connected, an attacker is using the same remote access infrastructure as authorised employees. A successful VPN login can consequently appear routine unless defenders examine the source network, client identifiers, account behaviour and actions occurring immediately after the connection.

Observed tradecraft has included forged authentication for privileged accounts such as admin, configuration retrieval and the establishment of IPsec connectivity. Attackers have then used techniques involving Impacket, NTLM relay and lateral movement inside Windows environments.

Products and versions affected by CVE-2026-0257

The GlobalProtect flaw affects configured portals and gateways across PAN-OS 12.1, 11.2, 11.1 and 10.2, as well as specified Prisma Access releases. Panorama and Cloud NGFW are not affected.

Palo Alto Networks lists the following fixed maintenance releases:

  • PAN-OS 12.1: 12.1.4-h6, 12.1.7 and later maintenance releases.
  • PAN-OS 11.2: 11.2.4-h17, 11.2.7-h14, 11.2.10-h7, 11.2.12 and later.
  • PAN-OS 11.1: 11.1.4-h33, 11.1.6-h32, 11.1.7-h6, 11.1.10-h25, 11.1.13-h5, 11.1.15 and later.
  • PAN-OS 10.2: 10.2.7-h34, 10.2.10-h36, 10.2.13-h21, 10.2.16-h7, 10.2.18-h6 and later.
  • Prisma Access: 11.2.7-h13 and 10.2.10-h36.

Administrators should compare their exact maintenance release with the vendor advisory rather than checking only the main PAN-OS branch. Prisma Access customers are upgraded according to the service schedule, while hybrid environments may still contain affected on-premises firewalls that require separate updates.

GlobalProtect flaw exploitation timeline

Palo Alto Networks published its advisory and fixes on 13 May 2026. Active exploitation was observed from at least 17 May 2026, according to reporting from Arctic Wolf and FortiGuard information referencing Rapid7 MDR observations.

On 29 May 2026, CISA added CVE-2026-0257 to its Known Exploited Vulnerabilities catalogue, confirming that the vulnerability was being used in real attacks. Arctic Wolf also reported that public proof-of-concept material appeared on that date.

Arctic Wolf issued a bulletin about increased exploitation on 4 June 2026. On 20 July 2026, it described multiple incidents from June 2026 in which the GlobalProtect flaw provided initial access before credential theft and domain-wide Qilin ransomware deployment. CyPro’s earlier Qilin ransomware bulletin covered those findings.

The 11 October 2026 ReliaQuest reporting broadens the apparent campaign picture by naming both Qilin and Settra. Qilin exploitation is supported by multiple investigated incidents, while Settra’s specific use of CVE-2026-0257 remains based on the ReliaQuest update cited in the report.

Activity observed after unauthorised VPN access

In the documented Qilin incidents, exploitation was not limited to creating a VPN connection. Operators stole credentials, moved across Windows systems and prepared the environment for ransomware deployment.

Arctic Wolf observed payloads staged in C:\PerfLogs, PsExec-based lateral execution, access to LSASS and NTDS data, and the clearing of Windows event logs. Attackers also installed remote access tools and transferred data to cloud storage before encryption.

Tools and services associated with activity following access included AnyDesk, Ngrok, LogMeIn and cloud storage such as MEGA. Some VPN clients used during exploitation identified themselves with hostnames such as kali. That hostname is an investigation lead rather than proof of compromise, as legitimate security testing systems may use the same value.

No campaign-specific IP addresses, domains or file hashes were identified in the reviewed vendor sources. Detection must therefore focus heavily on behaviour, including unusual hosting providers, unexpected VPN client details, rapid configuration access, credential dumping, remote service creation and lateral movement following a new connection.

What organisations should do now

Organisations with internet-facing GlobalProtect services should first determine whether authentication override cookies are generated or accepted on their portals and gateways. Affected systems should be upgraded to the appropriate fixed maintenance release, including every internal and external component that generates or accepts these cookies.

  • Disable authentication override cookies where they are not required.
  • If cookies remain enabled, generate a dedicated certificate used only for authentication override.
  • Do not reuse a portal, gateway or previously deployed service certificate for this function.
  • Terminate active GlobalProtect sessions after remediation and require users to authenticate again.
  • Investigate suspicious VPN sessions and the subsequent endpoint, identity and network activity.

Incomplete upgrades can cause cookie compatibility problems between GlobalProtect components. Patching also does not remove access already established before remediation, so session termination and investigation are essential parts of the response to this GlobalProtect flaw.

Originally reported by cybersecuritynews.com.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call