logo

Palo Alto Warns GlobalProtect VPN Flaw Is Being Actively Exploited

ID: 69756ce5-8ff2-521f-acc7-9ad2ffc146ad

STIX ID: report--69756ce5-8ff2-521f-acc7-9ad2ffc146ad

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-06-15

Date Updated: 2026-07-21

Author: Divya

...
...

Palo Alto Networks and Unit 42 warn of active exploitation of CVE-2026-0257 in GlobalProtect (PAN-OS), where attackers forge authentication cookies to bypass login and establish VPN sessions; multiple IOCs are provided, exploitation has been observed in the wild, and immediate patching, disabling authentication override, dedicated certificates, log review and threat hunting are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.