Security Advisory · Active Exploitation
Attackers can forge authentication cookies to access internal networks without valid credentials. Patches are available. Exploitation has been active since May 17, 2026.
How the attack works
/ssl-vpn/login.esp, the appliance decrypts it — but never verifies a digital signature. Whatever the decrypted payload claims, the server accepts.Attack timeline
aa:bb:cc:dd:ee observed across incidents.What to do — in order of priority
After patching, GlobalProtect users will need to re-authenticate once due to cookie regeneration logic in the fix.
Indicators of compromise
MITRE ATT&CK
References