Skip to main content
Cyber News & CTI Reports :: 2026-06-15 | Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw
Contact Page | Privacy Policy

2026-06-15 | Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw

1. AI Summary

entry_summary>Palo Alto Networks reported active exploitation of CVE-2026-0257, an authentication bypass in PAN‑OS, allowing attackers to bypass security controls and establish VPN sessions via GlobalProtect portals. The flaw, rated CVSS 7.8, was added to the US CISA KEV catalog and agencies must mitigate by June 1 2026. IOCs include nine malicious IP addresses and specific client configuration indicators from a PoC exploit.</entry_summary>

2. IOCs

IOC Type Value Description Relevant MITRE ATT&CK Techniques
Ipaddress
23.128.228.6
Observed IP address used in malicious activity targeting GlobalProtect portals exploiting CVE-2026-0257. T1071.001|T1190
Ipaddress
104.207.144.154
Observed IP address used in malicious activity targeting GlobalProtect portals exploiting CVE-2026-0257. T1071.001|T1190
Ipaddress
146.19.216.119
Observed IP address used in malicious activity targeting GlobalProtect portals exploiting CVE-2026-0257. T1071.001|T1190
Ipaddress
146.19.216.120
Observed IP address used in malicious activity targeting GlobalProtect portals exploiting CVE-2026-0257. T1071.001|T1190
Ipaddress
146.19.216.125
Observed IP address used in malicious activity targeting GlobalProtect portals exploiting CVE-2026-0257. T1071.001|T1190
Ipaddress
179.43.172.213
Observed IP address used in malicious activity targeting GlobalProtect portals exploiting CVE-2026-0257. T1071.001|T1190
Ipaddress
185.195.232.139
Observed IP address used in malicious activity targeting GlobalProtect portals exploiting CVE-2026-0257. T1071.001|T1190
Ipaddress
198.12.106.60
Observed IP address used in malicious activity targeting GlobalProtect portals exploiting CVE-2026-0257. T1071.001|T1190
Ipaddress
202.144.192.47
Observed IP address used in malicious activity targeting GlobalProtect portals exploiting CVE-2026-0257. T1071.001|T1190

3. MITRE ATT&CK

Code Title
T1190 Exploit Public-Facing Application
T1199 Exploit Software Vulnerability
T1071.001 Application Layer Protocol: Web Protocols - Application Layer Protocol (HTTPS) used for VPN communications

4. Targets

Type Value
Region Global

5. Article Details

6. Original text

Palo Alto Networks has revealed that it has observed "active exploitation" of a recently disclosed PAN-OS vulnerability by an unknown threat actor to obtain unauthorized access to

Global
Protect portals. The vulnerability in question is CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software that could be exploited by bad actors to set up VPN connections. According to the network security company, the security defect could be exploited by a bad actor to bypass security controls and initiate VPN connections. The vulnerability has been exploited in the wild in limited attacks, with initial activity observed on May 17, 2026. It's currently unknown who is behind the exploitation efforts. "No post-access behavior or lateral movement has been identified as of this time," Palo Alto Networks said . "Only a small portion of the probed devices actually established VPN sessions, resulting in gateway-connected events." The company has also released indicators of compromise (IoCs) associated with the activity - IP addresses - 23.128.228[.]6 104.207.144[.]154 146.19.216[.]119 146.19.216[.]120 146.19.216[.]125 179.43.172[.]213 185.195.232[.]139 198.12.106[.]60 202.144.192[.]47 Host Names and MAC Addresses - aa:bb:cc:dd:ee:ff 00:11:22:33:44:55 WINDOWS-LAPTOP-001 DESKTOP-GP01 GP-CLIENT Palo Alto Networks is also urging customers to search
Global
Protect logs for successful gateway-connected events that match the following hard-coded client configuration values from a proof-of-concept (PoC) exploit - endpoint_os_version : Microsoft Windows 10 Pro 64-bit source_user_info.domain : empty Late last month, the U.S. Cybersecurity and Infrastructure Security Agency (CSIA) added CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) catalog, ordering Federal Civilian Executive Branch (FCEB) agencies to mitigate the flaw by June 1, 2026.