PAN-OS GlobalProtect portal and gateway
CVE-2026-0257: GlobalProtect authentication bypass via forged override cookies
Attackers forge GlobalProtect authentication override cookies and open VPN sessions without credentials. Exploited since May 17, 2026, and used by Qilin ransomware affiliates for initial access.
Published Updated
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| PAN-OS 12.1 | 12.1.4-h6, 12.1.7 or later |
| PAN-OS 11.2 | 11.2.4-h17, 11.2.7-h14, 11.2.10-h7, 11.2.12 or later |
| PAN-OS 11.1 | 11.1.4-h33, 11.1.6-h32, 11.1.7-h6, 11.1.10-h25, 11.1.13-h5, 11.1.15 or later |
| PAN-OS 10.2 | 10.2.7-h34, 10.2.10-h36, 10.2.13-h21, 10.2.16-h7, 10.2.18-h6 or later |
| Older PAN-OS (end of life) | No fix. Upgrade to a supported fixed version |
| Prisma Access 10.2 / 11.2 | 10.2.10-h36 / 11.2.7-h13 or later |
| Cloud NGFW, Panorama | Not affected |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
GlobalProtect can issue an authentication override cookie after a user logs in, so the client can reconnect without asking for credentials (and MFA) again. On vulnerable versions, the portal and gateway decrypt that cookie and trust its contents without checking a signature.
The cookie is encrypted with a certificate’s public key. If that certificate is also used somewhere an outsider can read it, typically the portal or gateway’s own HTTPS certificate, anyone can build a valid-looking cookie for any user and open a VPN session. No password and no MFA.
That’s why the original medium rating was misleading. On a firewall with the risky configuration, this is a direct path into the internal network, and ransomware operators have used it exactly that way.
Am I affected?
You’re exposed only if all three are true:
- Your PAN-OS version is in the affected range (see the table above).
- A GlobalProtect portal or gateway has authentication override cookies enabled. This is off by default but widely used to cut down repeated MFA prompts.
- The certificate that encrypts the cookies is also used elsewhere, such as the portal or gateway’s SSL/TLS service profile.
Check your version (CLI):
show system info | match sw-version
Check whether override cookies are on. In the web interface:
- Portal: Network > GlobalProtect > Portals > your portal > Agent > your agent configuration > Authentication. Look at Generate cookie for authentication override and Accept cookie for authentication override.
- Gateway: Network > GlobalProtect > Gateways > your gateway > Agent > Client Settings > your profile > Authentication Override. Look at Accept cookie for authentication override.
Or from the CLI, list every override setting in one go:
set cli config-output-format set
configure
show | match authentication-override
Check the certificate. In the same authentication override settings, note the certificate used to encrypt and decrypt the cookie. If it’s the same certificate your portal or gateway presents over HTTPS, or one used by any other feature, treat the device as exploitable.
Prisma Access tenants on the affected versions are covered by the same advisory. Panorama and Cloud NGFW are not affected.
What to do
1. Upgrade. Move to a fixed hotfix on your branch. Pick the newest one available, not just the minimum listed here: later Palo Alto advisories, such as CVE-2026-0310 in September, need newer builds than this fix.
2. Upgrade every portal and gateway that issues or accepts cookies together. Palo Alto warns that mixing fixed and unfixed devices breaks cookie compatibility. For phased rollouts, the advisory FAQ describes a temporary setting (enable-auth-override-cookie-hmac no) that relaxes the new check on upgraded devices. Set it back to yes as soon as everything is upgraded, because the fix isn’t enforced until then.
3. Warn your helpdesk. After the upgrade, the firewall regenerates cookies with the new method, so every GlobalProtect user must log in again once, even with a valid cookie. Expect a wave of MFA prompts and tickets.
If you can’t upgrade tonight, use one of the vendor workarounds:
- Dedicated certificate: generate a new certificate used only for authentication override cookies. Don’t reuse the portal or gateway certificate, and don’t reuse any certificate that was ever used by another service. This keeps the feature working and closes the attack path.
- Disable authentication override: uncheck the generate and accept options on portals and gateways. This is the bluntest fix, but users will authenticate (and get MFA prompts) on every connection.
After patching: terminate active GlobalProtect sessions so any forged sessions are cut off, then hunt for past compromise (below). If you find a successful forged login, treat it as a network intrusion, not a VPN issue.
Detection
Exploitation leaves traces in the GlobalProtect logs (Monitor > Logs > GlobalProtect). Search back to at least May 17, 2026:
- Successful logins where the authentication method is Cookie, especially for local accounts such as
admin. Rapid7 saw forged cookies used against the local admin account across several customers. - A cookie decryption error followed by a successful login in the same session (Arctic Wolf).
- Successful logins from VPS hosting providers (such as Vultr), Tor exit nodes, or countries your users aren’t in.
- Client host names
kali,GP-CLIENT,DESKTOP-GP01,WINDOWS-LAPTOP-001orJocker, and placeholder MAC addressesaa:bb:cc:dd:ee:ffor00:11:22:33:44:55. - The public proof of concept’s fixed values: endpoint OS “Microsoft Windows 10 Pro 64-bit” with an empty domain field (Unit 42).
- In web or WAF logs: POSTs to
/ssl-vpn/login.espcarryingportal-userauthcookieorportal-prelogonuserauthcookie, followed by/ssl-vpn/getconfig.espand/ssl-vpn/hipreport.esp(Rapid7).
After VPN access, the observed activity was fast and noisy:
- SMB and NTLM authentication from VPN-assigned addresses to many hosts within minutes, including NTLM anonymous logons and Impacket-style reconnaissance.
- LSASS memory dumps and NTDS.dit extraction, then lateral movement with PsExec.
- In Qilin cases: the ransomware binary staged as
C:\PerfLogs\win.exe, AnyDesk, ngrok, rclone and the scheduled task\MeshUserTask.
Indicators of compromise
Most IP addresses are rented VPS servers that change owners. Use them to hunt for past activity in your logs, not as your only defense.
The .txt list has one IP per line and a fixed address, so a firewall can pull it as an External Dynamic List: https://patchtonight.com/iocs/CVE-2026-0257.txt
| Indicator | Type | Reported by |
|---|---|---|
| 23.128.228[.]6 | IP | Unit 42 |
| 104.207.144[.]154 | IP | Unit 42, Rapid7 |
| 146.19.216[.]119 | IP | Unit 42, Rapid7 |
| 146.19.216[.]120 | IP | Unit 42, Rapid7 |
| 146.19.216[.]125 | IP | Unit 42, Rapid7 |
| 179.43.172[.]213 | IP | Unit 42 |
| 185.195.232[.]139 | IP | Unit 42 |
| 198.12.106[.]60 | IP | Unit 42 |
| 202.144.192[.]47 | IP | Unit 42 |
| 209.99.191[.]137 | IP | Rapid7 |
| 79.130.26[.]202 | IP | Rapid7 |
| 108.61.229[.]217 | IPQilin ransomware intrusions | Arctic Wolf |
| 108.61.75[.]232 | IPQilin ransomware intrusions | Arctic Wolf |
| 2.188.33[.]52 | IPQilin ransomware intrusions | Arctic Wolf |
| 199.247.22[.]193 | IPQilin ransomware intrusions | Arctic Wolf |
| 70.34.205[.]43 | IPQilin ransomware intrusions | Arctic Wolf |
| kali | Host nameClient host name | Arctic Wolf |
| GP-CLIENT | Host nameClient host name | Unit 42, Rapid7, Arctic Wolf |
| DESKTOP-GP01 | Host nameClient host name | Unit 42, Rapid7, Arctic Wolf |
| WINDOWS-LAPTOP-001 | Host nameClient host name | Unit 42 |
| Jocker | Host nameClient host name | Rapid7 |
| aa:bb:cc:dd:ee:ff | MAC addressSpoofed client MAC address | Unit 42, Rapid7, Arctic Wolf |
| 00:11:22:33:44:55 | MAC addressSpoofed client MAC address | Unit 42 |
Sources
Page changelog
- Page published.
KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.