THN 9.1 CRITICAL

Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw_THN:23F3604E6D0C0EDC18C5C8E4FF76DDC8

9.1 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiMFIs6j0CgFzSojDqSi_UsqRzjlbYcRsrJG714Yh40TZXU4ZzlB_Do-7nbx5WGGvOS7mV3TojQLTiHbFS57BtgCo4hlF0DebzDtrSh5YzXkqNhjEI4JG97N_vpkFzeJP3V-adbSsPYRdYCQklFdweodtTJHywVHA5HiqgvYOp5eyxW0aQxKVacua9F9w3_/s1600/paloalto-vpn.jpg)

Palo Alto Networks has revealed that it has observed "active exploitation" of a recently disclosed PAN-OS vulnerability by an unknown threat actor to obtain unauthorized access to GlobalProtect portals.

The vulnerability in question is **CVE-2026-0257** (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software that could be exploited by bad actors to set up VPN connections.

According to the network security company, the security defect could be exploited by a bad actor to bypass security controls and initiate VPN connections.

The vulnerability has been exploited in the wild in limited attacks, with initial activity observed on May 17, 2026. It's currently unknown who is behind the exploitation efforts.

"No post-access behavior or lateral movement has been identified as of this time," Palo Alto Networks said. "Only a small portion of the probed devices actually established VPN sessions, resulting in gateway-connected events."

The company has also released indicators of compromise (IoCs) associated with the activity -

* IP addresses -
* 23.128.228[.]6
* 104.207.144[.]154
* 146.19.216[.]119
* 146.19.216[.]120
* 146.19.216[.]125
* 179.43.172[.]213
* 185.195.232[.]139
* 198.12.106[.]60
* 202.144.192[.]47
* Host Names and MAC Addresses -
* aa:bb:cc:dd:ee:ff
* 00:11:22:33:44:55
* WINDOWS-LAPTOP-001
* DESKTOP-GP01
* GP-CLIENT



Palo Alto Networks is also urging customers to search GlobalProtect logs for successful gateway-connected events that match the following hard-coded client configuration values from a proof-of-concept (PoC) exploit -

* endpoint_os_version : Microsoft Windows 10 Pro 64-bit
* source_user_info.domain : empty



Late last month, the U.S. Cybersecurity and Infrastructure Security Agency (CSIA) added CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) catalog, ordering Federal Civilian Executive Branch (FCEB) agencies to mitigate the flaw by June 1, 2026.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Visit Original Source

Basic Information

ID THN:23F3604E6D0C0EDC18C5C8E4FF76DDC8
Published Jun 15, 2026 at 06:17

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.