Palo Alto GlobalProtect has crossed the line from a security control to an attack vector. A run of critical, actively exploited flaws, from CVE-2024-3400 at CVSS 10.0 to CVE-2026-0257 forging authentication cookies to walk past MFA, plus mounting hardware end-of-life pressure, means an exposed GlobalProtect gateway is now a liability. Palo Alto’s own cloud route, Prisma Access, keeps the PAN-OS complexity, adds a steep licensing floor and still processes data under the US CLOUD Act. For a European mid-market team, a sovereign ZTNA platform is the stronger move, and Jimber is the best fit: one Belgian wealth manager cut security costs 58% doing exactly this.
Key takeaways
- GlobalProtect gateways have been hit by repeated pre-authentication zero-days; legacy VPNs were the entry point in 73% of verified ransomware attacks in 2025.
- CVE-2026-0257 lets an unauthenticated attacker forge authentication-override cookies and open a full VPN tunnel without triggering MFA, when the same certificate is reused for HTTPS and cookie encryption.
- Hardware EOL adds pressure: PA-220 units are stuck on PAN-OS 10.2, which reaches end of life on 31 March 2027.
- Prisma Access moves tunnel termination to the cloud but keeps the PAN-OS architecture, a 200-to-250 licence minimum, and GCP-hosted processing under the CLOUD Act.
- A phased move to sovereign ZTNA keeps your Palo Alto firewalls for local segmentation while closing the inbound VPN ports, dropping internet exposure to zero.
The GlobalProtect exploitation record
An SSL VPN needs a public port (usually TCP 443) open to the whole internet, which lets attackers scan and exploit pre-authentication flaws before any identity check happens. PAN-OS, which drives GlobalProtect, has been a repeated target.
| CVE | CVSS / CISA KEV | Impact |
|---|---|---|
| CVE-2024-3400 | 10.0 / 12 Apr 2024 | Unauthenticated command injection; code execution as root, exploited as a zero-day (Volexity), used by advanced actors for backdoors and lateral movement |
| CVE-2024-9465 | 9.1 / 14 Nov 2024 | SQL injection in the Expedition migration tool; unauthenticated theft of API keys and admin password hashes, reused against live gateways |
| CVE-2025-0108 | 8.8 / 18 Feb 2025 | Authentication bypass on the web interface; chained with other CVEs for full root access |
| CVE-2026-0257 | 9.1 / 29 May 2026 | Authentication bypass via forged override cookies; opens an administrative VPN tunnel without MFA |
CVE-2026-0257 shows the structural weakness clearly. GlobalProtect issues encrypted “authentication override” cookies so users are not prompted for MFA repeatedly. When administrators reuse the same SSL certificate for the HTTPS interface and for encrypting those cookies, an unauthenticated attacker can extract the public key from the TLS handshake and forge a valid-looking cookie for the local admin account, because the service decrypts and trusts the cookie contents without an additional signature or HMAC check. Rapid7 observed two exploitation waves in May 2026 assigning live VPN sessions. The lesson repeats across this list: patching helps, but the internet-facing gateway is the problem.
Hardware and PAN-OS end-of-life pressure
Beyond zero-days, lifecycle deadlines force the issue. Older appliances cannot run modern PAN-OS, so they get stranded on an OS train that is itself expiring.
| Product | End of life | Consequence |
|---|---|---|
| PAN-OS 10.2 | 31 March 2027 (extended) | The last OS for legacy hardware like the PA-220; after this, no security support |
| PAN-OS 11.0 | 17 November 2024 (passed) | No more updates or hotfixes |
| PA-220 appliance | 31 January 2028 | Cannot run PAN-OS 11.x; capped at 10.2, so it must be replaced or migrated by early 2027 |
| PA-800 series | 31 August 2029 | Caps at PAN-OS 11.1, whose EOL on 3 May 2027 shortens effective life |
When a firewall reaches EOL, its Threat Prevention, antivirus and URL-filtering databases stop updating too. The gateway goes blind to new attacks while its port stays open to the internet.
Three migration paths, compared
Removing the risk of an internet-exposed VPN gateway comes down to three routes.
| Criterion | A: Stay on Palo Alto (patch/harden) | B: Prisma Access (cloud SASE) | C: Sovereign ZTNA (Jimber) |
|---|---|---|---|
| Complexity | Continuous monitoring, manual patching, isolating management interfaces | High; keeps PAN-OS zones, templates and Panorama | Low; cloud-native, one console, no firewall zones |
| Cost | Predictable licences, but rising patch and incident overhead | Very high; credit-based, 200-to-250 licence minimum | Transparent per-user, no bandwidth or log surcharges |
| Security model | Inbound VPN port stays open to pre-auth attacks | Improved, but keeps the legacy L3/L4 tunnel | Applications hidden behind outbound connectors; no public listeners |
| Sovereignty | US vendor under the CLOUD Act | Processed via US cloud (GCP) | Belgian vendor; data stored and processed in the EU |
| OT & IoT | No native isolation for agentless devices | Limited to HTTP/HTTPS clientless VPN; no UDP | Native NIAC hardware isolates TCP and UDP legacy traffic |
Prisma Access moves the tunnel to Palo Alto’s cloud PoPs, which helps geographically spread teams, but the management model stays identical to a physical firewall, and for a mid-market shop the minimum-licence floor and mandatory QuickStart services push first-year entry costs to roughly $50,000 to $95,000 for fewer than 150 users. Jimber offers a linear per-user model from 50 users with no artificial thresholds. Our Prisma Access versus Jimber comparison goes deeper.
Mapping GlobalProtect to a Zero Trust model
Where GlobalProtect places a user directly on the network with broad Layer 3 rights, ZTNA grants access only at the application level. A migration translates each feature:
- Always-On VPN and Pre-Logon become continuous identity and device attestation through Entra ID, so the pre-logon firewall port can be closed once machine identities are validated.
- Per-app and clientless VPN become Web Application Isolation, where apps sit behind an outbound container proxy with no local install.
- Split tunneling becomes direct-to-cloud local breakout at the SASE edge.
- HIP checks become continuous posture assessment plus browser isolation.
The cutover is phased. The ZTNA client runs alongside GlobalProtect without network conflicts, you migrate user groups (for example, all external consultants first), and once Jimber enforces access you close the inbound ports and end the HIP licences. You do not have to scrap the Palo Alto firewalls, which can stay for local segmentation while remote access moves to Jimber. Our enterprise VPN end-of-life watchlist sets GlobalProtect in the wider context.
Proof from the field: a Belgian wealth manager
A Belgian wealth manager with over €450 million under management, supervised by the FSMA, replaced its fragmented security stack with Jimber over an eight-week, phased rollout. The results, detailed in our wealth-manager case study: a 58% cut in security costs by removing firewall and VPN hardware and support contracts, a 60% reduction in day-to-day admin time by moving from five point products to one console, and latency down from 85 ms to 12 ms by swapping VPN backhauling for local cloud breakouts. The NIAC isolated agentless office devices so a compromised printer could not pivot to systems holding client data, and a single audit trail simplified FSMA and NIS2 reporting. That is the pattern a GlobalProtect migration to Jimber follows.
Compliance, liability and insurance
Belgium’s NIS2 law has been in force since October 2024. Under Article 20, directors can be held personally liable, and knowingly running an unprotected, end-of-life or repeatedly-vulnerable VPN gateway can be treated as gross negligence, with the CCB able to suspend executives. Fines reach €10 million or 2% of global turnover for essential entities and €7 million or 1.4% for important entities. Insurers have tightened too: Belgian cyber cover runs €200 to €400 per user per year, and if a ransomware claim traces to a known, unpatched VPN flaw such as CVE-2026-0257, the insurer can refuse to pay on grounds of negligence. Moving to a sovereign SASE platform covers roughly 90% of the technical NIS2 requirements, which also eases insurer acceptance.
Frequently asked questions
Was disabling device telemetry an effective mitigation for CVE-2024-3400?
No. Palo Alto initially suggested that disabling device telemetry masked the flaw, then withdrew that guidance within days when research showed the command injection still worked regardless. The only effective mitigation was applying the official hotfixes or disabling the GlobalProtect gateway entirely.
What is the architectural difference between Prisma Access and on-premises GlobalProtect?
On-premises GlobalProtect terminates all VPN tunnels on your physical firewalls, causing hairpinning and extra CPU load. Prisma Access moves termination to Palo Alto’s cloud PoPs on GCP, which improves performance for spread-out teams, but the underlying management complexity, PAN-OS architecture, security zones and Panorama templates, stays identical.
How does Jimber secure unmanaged BYOD devices and external consultants without client software?
Jimber uses Web Application Isolation. Instead of opening a Layer 3 tunnel, BYOD users log in through a clientless web portal, application sessions run in an isolated cloud container, and the user interacts only with a safe visual stream, so malware on the device cannot reach the applications or their APIs.
How do we secure printers, IP cameras and OT that cannot run a VPN client?
Large SASE vendors rely on client agents and offer no native inline isolation for agentless devices. Jimber uses the NIAC, small hardware placed inline in front of the legacy device that enforces microsegmentation on both TCP and UDP traffic, such as Modbus TCP or BACnet over UDP, so a compromised device cannot move laterally.
Do we have to scrap our Palo Alto firewalls when migrating to Jimber?
No. The transition can be phased. The Palo Alto firewalls can stay for local network segmentation and routing while remote access moves to Jimber. Once the inbound VPN ports on the firewall are closed, internet-scan exposure drops to zero immediately.
How does Jimber’s data sovereignty compare with US vendors under the CLOUD Act?
US vendors such as Palo Alto fall under the CLOUD Act, which can compel them to hand over data they control even if it sits on European servers. Jimber is a fully Belgian entity that develops, hosts and manages its services entirely within the EU, which removes the risk of extraterritorial data demands and keeps audits cleanly GDPR-compliant.
Close the gateway before it closes you
If GlobalProtect faces the internet, assume it is being probed. Map your remote-access dependencies, run the ZTNA client alongside GlobalProtect, migrate user groups, and close the inbound ports. Book a Jimber demo to see a phased, EU-sovereign path off GlobalProtect, or compare pricing against a Prisma Access quote and its licence floor.