ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Palo Alto Warns of Active Exploitation of PAN

criticalExploit / PoC exploited in the wildimportance 60CVE-2026-0257

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-0257
Authentication Bypass in Palo Alto Networks PAN-OS GlobalProtect Portal and Gateway

CVE-2026-0257 is an authentication bypass in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS that allows a remote, unauthenticated attacker to defeat security restrictions and establish an unauthorized VPN connection; incident reporting indicates it involves forged VPN cookies (CWE-565). An attacker who succeeds gains the network access of a legitimate remote-access user, and Qilin ransomware affiliates have been using this flaw as their initial access vector. Any organization running PAN-OS with the GlobalProtect portal or gateway enabled is in scope, including Siemens RUGGEDCOM APE1808 appliances that run PAN-OS, while Panorama and Cloud NGFW are explicitly not affected. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2026-05-29 with ransomware use known, EPSS assigns it a 93.9% probability of exploitation within 30 days (100th percentile), and Rapid7 has documented attacks against multiple customers.

Do: Upgrade PAN-OS to the fixed release specified in the Palo Alto Networks security advisory, and check Siemens' guidance if you operate RUGGEDCOM APE1808 appliances. Review GlobalProtect portal/gateway logs for forged VPN cookies and unauthorized VPN sessions, and hunt for Qilin ransomware indicators on hosts reachable through the VPN. If patching cannot happen immediately, restrict internet exposure of the GlobalProtect portal and gateway; federal agencies must apply mitigations per BOD 22-01 given the KEV listing.

7.895% KEV ransomware
  • Palo Alto Networks PAN-OS (GlobalProtect portal and gateway)
  • Palo Alto Networks Prisma Access Listed in CPE data; affected status not detailed in source description, confirm with vendor advisory
  • Siemens RUGGEDCOM APE1808 firmware
massOn the order of hundreds of thousands of internet-exposed GlobalProtect portals/devices (mid-six figures)
Full article291 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJun 15, 2026Vulnerability / VPN Security

Palo Alto Networks has revealed that it has observed "active exploitation" of a recently disclosed PAN-OS vulnerability by an unknown threat actor to obtain unauthorized access to GlobalProtect portals.

The vulnerability in question is CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software that could be exploited by bad actors to set up VPN connections.

According to the network security company, the security defect could be exploited by a bad actor to bypass security controls and initiate VPN connections.

The vulnerability has been exploited in the wild in limited attacks, with initial activity observed on May 17, 2026. It's currently unknown who is behind the exploitation efforts.

"No post-access behavior or lateral movement has been identified as of this time," Palo Alto Networks said. "Only a small portion of the probed devices actually established VPN sessions, resulting in gateway-connected events."

The company has also released indicators of compromise (IoCs) associated with the activity -

  • IP addresses -
    • 23.128.228[.]6
    • 104.207.144[.]154
    • 146.19.216[.]119
    • 146.19.216[.]120
    • 146.19.216[.]125
    • 179.43.172[.]213
    • 185.195.232[.]139
    • 198.12.106[.]60
    • 202.144.192[.]47
  • Host Names and MAC Addresses -
    • aa:bb:cc:dd:ee:ff
    • 00:11:22:33:44:55
    • WINDOWS-LAPTOP-001
    • DESKTOP-GP01
    • GP-CLIENT

Palo Alto Networks is also urging customers to search GlobalProtect logs for successful gateway-connected events that match the following hard-coded client configuration values from a proof-of-concept (PoC) exploit -

  • endpoint_os_version : Microsoft Windows 10 Pro 64-bit
  • source_user_info.domain : empty

Late last month, the U.S. Cybersecurity and Infrastructure Security Agency (CSIA) added CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) catalog, ordering Federal Civilian Executive Branch (FCEB) agencies to mitigate the flaw by June 1, 2026.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/06/palo-alto-warns-of-active-exploitation.html