Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw

6 hours ago 13

Ravie LakshmananJun 15, 2026Vulnerability / VPN Security

Palo Alto Networks has revealed that it has observed "active exploitation" of a recently disclosed PAN-OS vulnerability by an unknown threat actor to obtain unauthorized access to GlobalProtect portals.

The vulnerability in question is CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software that could be exploited by bad actors to set up VPN connections.

According to the network security company, the security defect could be exploited by a bad actor to bypass security controls and initiate VPN connections.

The vulnerability has been exploited in the wild in limited attacks, with initial activity observed on May 17, 2026. It's currently unknown who is behind the exploitation efforts.

"No post-access behavior or lateral movement has been identified as of this time," Palo Alto Networks said. "Only a small portion of the probed devices actually established VPN sessions, resulting in gateway-connected events."

Cybersecurity

The company has also released indicators of compromise (IoCs) associated with the activity -

  • IP addresses -
    • 23.128.228[.]6
    • 104.207.144[.]154
    • 146.19.216[.]119
    • 146.19.216[.]120
    • 146.19.216[.]125
    • 179.43.172[.]213
    • 185.195.232[.]139
    • 198.12.106[.]60
    • 202.144.192[.]47
  • Host Names and MAC Addresses -
    • aa:bb:cc:dd:ee:ff
    • 00:11:22:33:44:55
    • WINDOWS-LAPTOP-001
    • DESKTOP-GP01
    • GP-CLIENT

Palo Alto Networks is also urging customers to search GlobalProtect logs for successful gateway-connected events that match the following hard-coded client configuration values from a proof-of-concept (PoC) exploit -

  • endpoint_os_version : Microsoft Windows 10 Pro 64-bit
  • source_user_info.domain : empty

Late last month, the U.S. Cybersecurity and Infrastructure Security Agency (CSIA) added CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) catalog, ordering Federal Civilian Executive Branch (FCEB) agencies to mitigate the flaw by June 1, 2026.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Read Entire Article