INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Palo Alto Auth Bypass Bug Exploit Under Active Threat

| 2026-06-01 08:30 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The threat landscape is rapidly evolving, with new vulnerabilities and exploits emerging daily. The recent incident involving China's TA4922 Expands Cybercrime Attacks Globally has highlighted the importance of staying vigilant against cyber threats. As organizations continue to upgrade their security technology in response to this vulnerability, it's essential for them to prioritize patching and mitigations to minimize the risk of successful attacks. With attackers exploiting vulnerabilities like authentication override in Palo Alto Networks' PAN-OS GlobalProtect VPN technology, timely updates are crucial to prevent lateral movement and data breaches.
Technical Mitigations AI-generated
* Configure GlobalProtect gateways to use a secure certificate that is not the same as the HTTPS service's certificate, and ensure certificates used for cookie encryption do not match those used for HTTPS services. * Implement a secure authentication override configuration, where cookies issued by the portal or gateway are encrypted with a different certificate than those used for HTTPS services.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-0257CVE-2026-0257 CVE-2025-0108CVE-2025-0108
Target & Sectors
CN CZ
Incident Timeline
‎May 18 and 21
Threat actors exploited the Palo Alto Auth Bypass Flaw in two waves, likely by the same actor, starting May 18 and 21.
‎2026/05/02
Threat actors are using a recently patched vulnerability in Palo Alto Auth to target vulnerable systems.
‎May 17
Threat actors exploited a vulnerability in Palo Alto Auth, identified by Rapid7 as early as May 17.
‎May 17, 2026
Threat actors exploited a Palo Alto Auth Bypass Flaw in attacks targeting systems as early as May 17, 2026.
‎May 18
Threat actors exploited a vulnerability in Palo Alto Auth's infrastructure to target Vultr on May 18.
organisation Vultr
organisation Dromatics Systems
‎May 21
Threat actors used Vultr infrastructure to exploit a Palo Alto Auth Bypass Flaw on May 21.
organisation Vultr
organisation Dromatics Systems
‎2026/05/25
Threat actors exploited the Palo Alto Auth Bypass Flaw in attacks that targeted unpatched devices without mitigations applied.
vulnerability CVE-2026-0257
organisation Palo Alto Networks
‎May 29
Threat actors exploited the Palo Alto Auth Bypass Flaw in May.
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
‎May 29, 2026
Threat actors exploited a vulnerability in Palo Alto Auth Bypass to target systems.
‎June 1
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-0257 to its Known Exploited Vulnerabilities Catalog, requiring federal civilian agencies to patch it by June 1.
source_region United States
vulnerability CVE-2026-0257
attribution CVE-2026
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
‎June 1, 2026
Threat actors exploited a known vulnerability in Palo Alto Auth.
attribution Known Exploited Vulnerability
‎2026/06/01
Threat actors exploited a vulnerability in Palo Alto Auth Bypass Flaw Exploited in Attacks, specifically CVE-2026-0257 found in PAN-OS software.
organisation CVE-2026-0257
organisation GlobalProtect
organisation PAN
organisation CVSS
organisation IP
organisation MDR
organisation GlobalProtect VPN
organisation TA4922 Expands Cybercrime Attacks Globally
organisation Apply Cybersecurity Mitigations
organisation Palo Alto Networks
organisation Another Palo Alto Auth Bypass Bug Under
organisation PoC
organisation State
organisation PHP
organisation AI-Assisted Exploit Development Outpaces
organisation Palo Alto GlobalProtect VPN auth
organisation PAN-OS's
organisation HTTPS
Intelligence Sources