entry_summary>Palo Alto Networks reported active exploitation of CVE-2026-0257, an authentication bypass in PAN‑OS, allowing attackers to bypass security controls and establish VPN sessions via GlobalProtect portals. The flaw, rated CVSS 7.8, was added to the US CISA KEV catalog and agencies must mitigate by June 1 2026. IOCs include nine malicious IP addresses and specific client configuration indicators from a PoC exploit.</entry_summary>
| IOC Type | Value | Description | Relevant MITRE ATT&CK Techniques |
|---|---|---|---|
| Ipaddress |
23.128.228.6
|
Observed IP address used in malicious activity targeting GlobalProtect portals exploiting CVE-2026-0257. | T1071.001|T1190 |
| Ipaddress |
104.207.144.154
|
Observed IP address used in malicious activity targeting GlobalProtect portals exploiting CVE-2026-0257. | T1071.001|T1190 |
| Ipaddress |
146.19.216.119
|
Observed IP address used in malicious activity targeting GlobalProtect portals exploiting CVE-2026-0257. | T1071.001|T1190 |
| Ipaddress |
146.19.216.120
|
Observed IP address used in malicious activity targeting GlobalProtect portals exploiting CVE-2026-0257. | T1071.001|T1190 |
| Ipaddress |
146.19.216.125
|
Observed IP address used in malicious activity targeting GlobalProtect portals exploiting CVE-2026-0257. | T1071.001|T1190 |
| Ipaddress |
179.43.172.213
|
Observed IP address used in malicious activity targeting GlobalProtect portals exploiting CVE-2026-0257. | T1071.001|T1190 |
| Ipaddress |
185.195.232.139
|
Observed IP address used in malicious activity targeting GlobalProtect portals exploiting CVE-2026-0257. | T1071.001|T1190 |
| Ipaddress |
198.12.106.60
|
Observed IP address used in malicious activity targeting GlobalProtect portals exploiting CVE-2026-0257. | T1071.001|T1190 |
| Ipaddress |
202.144.192.47
|
Observed IP address used in malicious activity targeting GlobalProtect portals exploiting CVE-2026-0257. | T1071.001|T1190 |
| Code | Title |
|---|---|
| T1190 | Exploit Public-Facing Application |
| T1199 | Exploit Software Vulnerability |
| T1071.001 | Application Layer Protocol: Web Protocols - Application Layer Protocol (HTTPS) used for VPN communications |
| Type | Value |
|---|---|
| Region | Global |
Palo Alto Networks has revealed that it has observed "active exploitation" of a recently disclosed PAN-OS vulnerability by an unknown threat actor to obtain unauthorized access to