Join our Newsletter — 33% off our NHI Course

GlobalProtect bypass: are your access controls still one-time trust?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: CVE-2026-0257 in Palo Alto GlobalProtect has been confirmed in the wild, according to Pomerium, with Rapid7 tracing successful attacks back to at least May 17 and CISA adding the flaw to its KEV catalog. One-time edge authentication turns a forged trust token into network reachability, so the real failure is a perimeter model that grants too much for too long.

Editorial analysis by NHI Mgmt Group, based on content published by Pomerium: “Another GlobalProtect bypass, another reminder that the VPN is the wrong place to put your trust”.

Key questions

Q: What breaks when a VPN gateway treats one login as durable trust?

A: The control breaks at the point where a successful edge authentication is allowed to imply broad internal reachability.

Q: Why do forged VPN trust tokens create such a large risk?

A: Because they let an attacker inherit the trust of the gateway without proving identity in a live, request-specific way.

Q: What are the signs that remote access controls are too broad for sensitive internal systems?

A: Remote access is too broad when users can reach more systems, files, or functions than their job requires, especially if clipboard, file transfer, or unrestricted shell access is left open by default.

Practitioner guidance

  • Audit trust-token handling at the edge Verify whether authentication override cookies, session tokens, or similar bearer artefacts can be minted, replayed, or reused without fresh policy evaluation.
  • Separate connectivity from authorisation Reduce the number of systems where one login event creates broad IP-level reachability, and prefer controls that scope access to a specific application or request.
  • Review certificate-signing overlap Check whether the same certificate or trust anchor signs both authentication material and unrelated web services, because that design can collapse token authenticity checks.

Bottom line: The article shows that the main problem is not only a vulnerability in GlobalProtect, but a VPN model that lets one trust decision open a broad internal path.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 21 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

Perimeter trust is a brittle identity assumption, not a security strategy. The article shows that a single authentication event at the edge can be converted into full network reachability, which is the core flaw in VPN-centric access design. Once that trust is granted, the model no longer distinguishes between a legitimate session and a compromised one. Practitioners should treat network placement as an outdated security primitive, not a durable control.

A few things that frame the scale:

  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, which means many teams cannot reliably tell where standing access still exists.

A question worth separating out:

Q: What should organisations do when a VPN bypass exposes the weakness of edge-based trust?

A: Shift the highest-value applications away from network-wide access and toward identity-aware, request-scoped authorization. Use the incident as a trigger to narrow what a session can reach, reduce the value of any single token, and ensure that no gateway failure can become an internal network breach.

👉 Read our full editorial: GlobalProtect bypass shows why VPN trust is the wrong model



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

Perimeter trust is a brittle identity assumption, not a security strategy. The article shows that a single authentication event at the edge can be converted into full network reachability, which is the core flaw in VPN-centric access design. Once that trust is granted, the model no longer distinguishes between a legitimate session and a compromised one. Practitioners should treat network placement as an outdated security primitive, not a durable control.

A few things that frame the scale:

  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, which means many teams cannot reliably tell where standing access still exists.

A question worth separating out:

Q: What should organisations do when a VPN bypass exposes the weakness of edge-based trust?

A: Shift the highest-value applications away from network-wide access and toward identity-aware, request-scoped authorization. Use the incident as a trigger to narrow what a session can reach, reduce the value of any single token, and ensure that no gateway failure can become an internal network breach.

👉 Read our full editorial: GlobalProtect bypass shows why VPN trust is the wrong model



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

One-time VPN trust is an assumption, not a control. The GlobalProtect case shows what happens when a perimeter device is allowed to turn one authentication event into enduring internal reachability. That model assumes the trust decision made at the edge remains valid after the session begins, which is exactly where it fails. For identity programmes, the lesson is that reachability must be evaluated as an access state, not a one-time proof.

A question worth separating out:

Q: How should teams respond when edge authentication can be bypassed?

A: Treat the bypass as evidence that network access and application access are too tightly coupled. Contain the exposure by narrowing what a session can reach, reviewing all routes opened by the gateway, and moving high-value services behind request-level policy instead of perimeter trust.

👉 Read our full editorial: GlobalProtect bypass shows why VPN trust is the wrong model


This post was modified 21 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.