Migrating Off Palo Alto GlobalProtect: Options After the VPN-CVE Wave

GlobalProtect faces active CVEs and hardware EOL. Why Prisma Access keeps the risk and how a sovereign ZTNA migration wins for the EU mid-market in 2026.
Financial-services security lead bij kantoorvenster met tablet

Palo Alto GlobalProtect has crossed the line from a security control to an attack vector. A run of critical, actively exploited flaws, from CVE-2024-3400 at CVSS 10.0 to CVE-2026-0257 forging authentication cookies to walk past MFA, plus mounting hardware end-of-life pressure, means an exposed GlobalProtect gateway is now a liability. Palo Alto’s own cloud route, Prisma Access, keeps the PAN-OS complexity, adds a steep licensing floor and still processes data under the US CLOUD Act. For a European mid-market team, a sovereign ZTNA platform is the stronger move, and Jimber is the best fit: one Belgian wealth manager cut security costs 58% doing exactly this.

Key takeaways

  • GlobalProtect gateways have been hit by repeated pre-authentication zero-days; legacy VPNs were the entry point in 73% of verified ransomware attacks in 2025.
  • CVE-2026-0257 lets an unauthenticated attacker forge authentication-override cookies and open a full VPN tunnel without triggering MFA, when the same certificate is reused for HTTPS and cookie encryption.
  • Hardware EOL adds pressure: PA-220 units are stuck on PAN-OS 10.2, which reaches end of life on 31 March 2027.
  • Prisma Access moves tunnel termination to the cloud but keeps the PAN-OS architecture, a 200-to-250 licence minimum, and GCP-hosted processing under the CLOUD Act.
  • A phased move to sovereign ZTNA keeps your Palo Alto firewalls for local segmentation while closing the inbound VPN ports, dropping internet exposure to zero.

The GlobalProtect exploitation record

An SSL VPN needs a public port (usually TCP 443) open to the whole internet, which lets attackers scan and exploit pre-authentication flaws before any identity check happens. PAN-OS, which drives GlobalProtect, has been a repeated target.

CVE CVSS / CISA KEV Impact
CVE-2024-3400 10.0 / 12 Apr 2024 Unauthenticated command injection; code execution as root, exploited as a zero-day (Volexity), used by advanced actors for backdoors and lateral movement
CVE-2024-9465 9.1 / 14 Nov 2024 SQL injection in the Expedition migration tool; unauthenticated theft of API keys and admin password hashes, reused against live gateways
CVE-2025-0108 8.8 / 18 Feb 2025 Authentication bypass on the web interface; chained with other CVEs for full root access
CVE-2026-0257 9.1 / 29 May 2026 Authentication bypass via forged override cookies; opens an administrative VPN tunnel without MFA

CVE-2026-0257 shows the structural weakness clearly. GlobalProtect issues encrypted “authentication override” cookies so users are not prompted for MFA repeatedly. When administrators reuse the same SSL certificate for the HTTPS interface and for encrypting those cookies, an unauthenticated attacker can extract the public key from the TLS handshake and forge a valid-looking cookie for the local admin account, because the service decrypts and trusts the cookie contents without an additional signature or HMAC check. Rapid7 observed two exploitation waves in May 2026 assigning live VPN sessions. The lesson repeats across this list: patching helps, but the internet-facing gateway is the problem.

Hardware and PAN-OS end-of-life pressure

Beyond zero-days, lifecycle deadlines force the issue. Older appliances cannot run modern PAN-OS, so they get stranded on an OS train that is itself expiring.

Product End of life Consequence
PAN-OS 10.2 31 March 2027 (extended) The last OS for legacy hardware like the PA-220; after this, no security support
PAN-OS 11.0 17 November 2024 (passed) No more updates or hotfixes
PA-220 appliance 31 January 2028 Cannot run PAN-OS 11.x; capped at 10.2, so it must be replaced or migrated by early 2027
PA-800 series 31 August 2029 Caps at PAN-OS 11.1, whose EOL on 3 May 2027 shortens effective life

When a firewall reaches EOL, its Threat Prevention, antivirus and URL-filtering databases stop updating too. The gateway goes blind to new attacks while its port stays open to the internet.

Three migration paths, compared

Removing the risk of an internet-exposed VPN gateway comes down to three routes.

Criterion A: Stay on Palo Alto (patch/harden) B: Prisma Access (cloud SASE) C: Sovereign ZTNA (Jimber)
Complexity Continuous monitoring, manual patching, isolating management interfaces High; keeps PAN-OS zones, templates and Panorama Low; cloud-native, one console, no firewall zones
Cost Predictable licences, but rising patch and incident overhead Very high; credit-based, 200-to-250 licence minimum Transparent per-user, no bandwidth or log surcharges
Security model Inbound VPN port stays open to pre-auth attacks Improved, but keeps the legacy L3/L4 tunnel Applications hidden behind outbound connectors; no public listeners
Sovereignty US vendor under the CLOUD Act Processed via US cloud (GCP) Belgian vendor; data stored and processed in the EU
OT & IoT No native isolation for agentless devices Limited to HTTP/HTTPS clientless VPN; no UDP Native NIAC hardware isolates TCP and UDP legacy traffic

Prisma Access moves the tunnel to Palo Alto’s cloud PoPs, which helps geographically spread teams, but the management model stays identical to a physical firewall, and for a mid-market shop the minimum-licence floor and mandatory QuickStart services push first-year entry costs to roughly $50,000 to $95,000 for fewer than 150 users. Jimber offers a linear per-user model from 50 users with no artificial thresholds. Our Prisma Access versus Jimber comparison goes deeper.

Mapping GlobalProtect to a Zero Trust model

Where GlobalProtect places a user directly on the network with broad Layer 3 rights, ZTNA grants access only at the application level. A migration translates each feature:

  • Always-On VPN and Pre-Logon become continuous identity and device attestation through Entra ID, so the pre-logon firewall port can be closed once machine identities are validated.
  • Per-app and clientless VPN become Web Application Isolation, where apps sit behind an outbound container proxy with no local install.
  • Split tunneling becomes direct-to-cloud local breakout at the SASE edge.
  • HIP checks become continuous posture assessment plus browser isolation.

The cutover is phased. The ZTNA client runs alongside GlobalProtect without network conflicts, you migrate user groups (for example, all external consultants first), and once Jimber enforces access you close the inbound ports and end the HIP licences. You do not have to scrap the Palo Alto firewalls, which can stay for local segmentation while remote access moves to Jimber. Our enterprise VPN end-of-life watchlist sets GlobalProtect in the wider context.

Proof from the field: a Belgian wealth manager

A Belgian wealth manager with over €450 million under management, supervised by the FSMA, replaced its fragmented security stack with Jimber over an eight-week, phased rollout. The results, detailed in our wealth-manager case study: a 58% cut in security costs by removing firewall and VPN hardware and support contracts, a 60% reduction in day-to-day admin time by moving from five point products to one console, and latency down from 85 ms to 12 ms by swapping VPN backhauling for local cloud breakouts. The NIAC isolated agentless office devices so a compromised printer could not pivot to systems holding client data, and a single audit trail simplified FSMA and NIS2 reporting. That is the pattern a GlobalProtect migration to Jimber follows.

Compliance, liability and insurance

Belgium’s NIS2 law has been in force since October 2024. Under Article 20, directors can be held personally liable, and knowingly running an unprotected, end-of-life or repeatedly-vulnerable VPN gateway can be treated as gross negligence, with the CCB able to suspend executives. Fines reach €10 million or 2% of global turnover for essential entities and €7 million or 1.4% for important entities. Insurers have tightened too: Belgian cyber cover runs €200 to €400 per user per year, and if a ransomware claim traces to a known, unpatched VPN flaw such as CVE-2026-0257, the insurer can refuse to pay on grounds of negligence. Moving to a sovereign SASE platform covers roughly 90% of the technical NIS2 requirements, which also eases insurer acceptance.

Frequently asked questions

Was disabling device telemetry an effective mitigation for CVE-2024-3400?

No. Palo Alto initially suggested that disabling device telemetry masked the flaw, then withdrew that guidance within days when research showed the command injection still worked regardless. The only effective mitigation was applying the official hotfixes or disabling the GlobalProtect gateway entirely.

What is the architectural difference between Prisma Access and on-premises GlobalProtect?

On-premises GlobalProtect terminates all VPN tunnels on your physical firewalls, causing hairpinning and extra CPU load. Prisma Access moves termination to Palo Alto’s cloud PoPs on GCP, which improves performance for spread-out teams, but the underlying management complexity, PAN-OS architecture, security zones and Panorama templates, stays identical.

How does Jimber secure unmanaged BYOD devices and external consultants without client software?

Jimber uses Web Application Isolation. Instead of opening a Layer 3 tunnel, BYOD users log in through a clientless web portal, application sessions run in an isolated cloud container, and the user interacts only with a safe visual stream, so malware on the device cannot reach the applications or their APIs.

How do we secure printers, IP cameras and OT that cannot run a VPN client?

Large SASE vendors rely on client agents and offer no native inline isolation for agentless devices. Jimber uses the NIAC, small hardware placed inline in front of the legacy device that enforces microsegmentation on both TCP and UDP traffic, such as Modbus TCP or BACnet over UDP, so a compromised device cannot move laterally.

Do we have to scrap our Palo Alto firewalls when migrating to Jimber?

No. The transition can be phased. The Palo Alto firewalls can stay for local network segmentation and routing while remote access moves to Jimber. Once the inbound VPN ports on the firewall are closed, internet-scan exposure drops to zero immediately.

How does Jimber’s data sovereignty compare with US vendors under the CLOUD Act?

US vendors such as Palo Alto fall under the CLOUD Act, which can compel them to hand over data they control even if it sits on European servers. Jimber is a fully Belgian entity that develops, hosts and manages its services entirely within the EU, which removes the risk of extraterritorial data demands and keeps audits cleanly GDPR-compliant.

Close the gateway before it closes you

If GlobalProtect faces the internet, assume it is being probed. Map your remote-access dependencies, run the ZTNA client alongside GlobalProtect, migrate user groups, and close the inbound ports. Book a Jimber demo to see a phased, EU-sovereign path off GlobalProtect, or compare pricing against a Prisma Access quote and its licence floor.

Find out how we can protect your business

In our demo call we’ll show you how our technology works and how it can help you secure your data from cyber threats.

Cybersecurity
Are you an integrator or distributor?

Need an affordable cybersecurity solution for your customers?

We’d love to help you get your customers on board.

checkmark

White glove onboarding

checkmark

Team trainings

checkmark

Dedicated customer service rep

checkmark

Invoices for each client

checkmark

Security and Privacy guaranteed