Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257

June 8, 2026, 8:53 a.m.

Description

An unidentified threat actor is actively exploiting CVE-2026-0257, an authentication bypass vulnerability in PAN-OS GlobalProtect portal and gateway components. The flaw allows unauthorized attackers to circumvent security controls and initiate VPN connections. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on May 29, 2026. Exploitation activity has been detected targeting GlobalProtect, with a small portion of probed devices successfully establishing VPN sessions. No post-access behavior or lateral movement has been identified. Organizations are advised to hunt for indicators including specific IP addresses, suspicious host IDs, and MAC addresses. Palo Alto Networks recommends following security advisory guidance, implementing available workarounds, and upgrading to patched versions.

Date

  • Created: June 5, 2026, 5:40 p.m.
  • Published: June 5, 2026, 5:40 p.m.
  • Modified: June 8, 2026, 8:53 a.m.

Indicators

  • 202.144.192.47
  • 104.207.144.154
  • 179.43.172.213
  • 23.128.228.6
  • 146.19.216.120
  • 185.195.232.139
  • 146.19.216.119
  • 146.19.216.125
  • 198.12.106.60

Attack Patterns

Linked vulnerabilities