Ransomware operators are abusing a Palo Alto Networks GlobalProtect authentication-bypass flaw to enter corporate networks through the VPN itself. The vulnerability, CVE-2026-0257, can let an unauthenticated attacker establish a VPN session on affected PAN-OS and Prisma Access deployments when a specific authentication-override configuration is present.
That makes this more dangerous than a normal failed-login problem. The attacker can arrive through a trusted remote-access path and initially look more like a legitimate remote user than an obvious internet scan. New reporting on October 11 says ransomware activity tied to the flaw is continuing, while earlier incident-response work independently documented intrusions that progressed all the way to Qilin ransomware.
Palo Alto Networks’ advisory now rates CVE-2026-0257 High at 7.8, marks it as attacked in the wild, and gives it the vendor’s highest response urgency. The flaw affects GlobalProtect portal and gateway deployments under specific configuration conditions; Panorama and Cloud NGFW are not affected.

The VPN can become the attacker’s front door
GlobalProtect is designed to put remote users onto private networks after authentication. That basic architecture is explained in BitcoinVersus’ What Is a VPN? guide. CVE-2026-0257 matters because the vulnerable configuration can let an attacker get past that gate without presenting valid credentials in the normal way.
The issue involves GlobalProtect authentication-override cookies. Those cookies are meant to let a previously authenticated user reconnect without repeating the full login process every time. In vulnerable deployments, weaknesses in how those cookies are validated can allow a forged cookie to be accepted as proof of authentication.
Why MFA does not replace the patch
Multi-factor authentication is still one of the most important defenses against stolen passwords. BitcoinVersus recently broke down how MFA adds a second proof of identity. But an authentication-bypass vulnerability changes the problem: if the vulnerable gateway accepts forged authentication state, adding another login factor does not repair the faulty validation path.
This is why the remediation starts with the affected GlobalProtect configuration and software version, not with telling users to choose stronger passwords. Palo Alto recommends upgrading to a fixed release, disabling authentication-override cookies when they are unnecessary, or using a new certificate dedicated exclusively to authentication override where the feature remains required.
Qilin attacks show what can happen after VPN access
The biggest change since the flaw was first disclosed is the evidence around what happens after a successful VPN connection. Arctic Wolf later documented multiple June intrusions where CVE-2026-0257 was the initial access vector before credential theft, lateral movement, Active Directory compromise, and Qilin ransomware deployment.
A new October 11 review from CyPro separates what is strongly corroborated from newer attribution claims. Qilin’s use of the flaw is backed by multiple investigated incidents. The newer claim that Settra is also exploiting CVE-2026-0257 comes from current ReliaQuest reporting and should be treated as reported attribution rather than independently established fact.
The post-entry behavior matters because a successful VPN session is only the first step. Once inside, attackers can begin credential discovery, Active Directory reconnaissance, administrative-share movement, remote tool deployment, data theft, or ransomware staging. Security teams therefore have to investigate suspicious successful VPN sessions, not just failed logins.
Authentication cookies deserve the same respect as passwords
An authentication cookie is effectively a short-lived bearer credential: possession can be enough to convince a service that the user has already authenticated. That is why the same security principle behind BitcoinVersus’ guide on protecting SSO and API tokens from theft also applies here. Identity is not only a username and password; session state can be just as valuable to an attacker.
What administrators should verify now
- Software: Compare every internet-facing GlobalProtect portal and gateway against Palo Alto Networks’ current fixed-version table.
- Configuration: Determine whether authentication-override cookies are enabled and whether the certificate setup matches the vulnerable condition.
- Sessions: After remediation, terminate active sessions so previously established access does not simply remain alive.
- Logs: Review successful cookie-based VPN connections, unexpected hostnames, unusual source infrastructure, and follow-on internal activity.
- Endpoints and identity: Check for credential theft, reconnaissance, remote administration tools, lateral movement, and ransomware staging after suspicious VPN access.
The important operational lesson is that patching the firewall and investigating the network are separate jobs. An upgrade closes the vulnerable path going forward; it does not prove that an attacker did not already establish a session or steal credentials before the fix.
A VPN vulnerability is really an identity-boundary failure
CVE-2026-0257 is a useful example of why edge security cannot be reduced to a CVSS number. The technical bug is an authentication bypass. The business impact is much larger: the device that decides who is allowed inside the private network can be tricked into admitting someone who never completed the intended authentication process.
That is why the right response is layered: patch the vulnerable software, correct the authentication-override configuration, invalidate existing sessions, and then hunt for evidence of what happened after any suspicious connection. With ransomware operators already demonstrating the full attack chain, this is no longer a theoretical VPN bug.
BitcoinVersus.Tech Editor’s Note: CVE-2026-0257 is configuration-dependent; not every GlobalProtect deployment is vulnerable. Qilin exploitation is independently documented. Newer Settra attribution is currently based on ReliaQuest reporting and is presented here with that limitation.
Follow BitcoinVersus.Tech on X for cybersecurity, networking, Linux, Bitcoin mining, semiconductor, and data-center reporting.
Support independent technology reporting: Bitcoin donations help fund BitcoinVersus.Tech research and publishing.
Disclaimer: BitcoinVersus.Tech provides technology news and analysis for informational purposes only.

Leave a Reply