Back to News
Vulnerabilities

Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw

Cyber RTJune 15, 20263 min read
Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw

Palo Alto Networks has identified active exploitation of a PAN-OS vulnerability, CVE-2026-0257, by an unknown threat actor to access GlobalProtect portals. This authentication bypass flaw, with a CVSS score of 7.8, allows unauthorized VPN connections. Initial attacks were observed on May 17, 2026, with limited exploitation. No lateral movement has been detected. The U.S. CSIA has mandated mitigation by June 1, 2026.

Palo Alto Networks has reported the active exploitation of a vulnerability in its PAN-OS software, specifically targeting GlobalProtect portals. This vulnerability, identified as CVE-2026-0257, has a CVSS score of 7.8, indicating a high level of severity. The flaw is an authentication bypass issue that could allow unauthorized users to establish VPN connections, thereby compromising security controls. The exploitation of this vulnerability has been observed in the wild, with initial activities recorded on May 17, 2026. However, the identity of the threat actor behind these attacks remains unknown. The attacks have been limited in scope, with only a few devices being successfully compromised to establish VPN sessions. Palo Alto Networks has noted that there has been no evidence of post-access behavior or lateral movement by the attackers at this time. To assist in identifying potential compromises, Palo Alto Networks has released a list of indicators of compromise (IoCs). These include specific IP addresses and host names that have been associated with the malicious activity. The company advises organizations to monitor their systems for these indicators to detect any unauthorized access attempts. In addition to the IoCs, Palo Alto Networks recommends that customers review their GlobalProtect logs for any successful gateway-connected events. These events should be cross-referenced with specific client configuration values from a proof-of-concept exploit, such as the operating system version and domain information, to identify potential breaches. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has also taken action in response to this vulnerability. CVE-2026-0257 has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog. Federal Civilian Executive Branch (FCEB) agencies have been instructed to mitigate this flaw by June 1, 2026, to prevent further exploitation. Palo Alto Networks is actively working to address this security issue and is urging its customers to implement the necessary mitigations. The company emphasizes the importance of staying vigilant and ensuring that all security patches are up to date to protect against potential threats. For those interested in staying informed about similar security issues and updates, Palo Alto Networks encourages following their content on platforms like Google News, Twitter, and LinkedIn. This ensures that users receive timely information about emerging threats and security best practices.