logo

Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw

ID: a1d620ae-a66e-5e5e-8450-16e30a0d47c4

STIX ID: report--a1d620ae-a66e-5e5e-8450-16e30a0d47c4

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2026-06-15

Date Updated: 2026-06-15

Author: [email protected] (The Hacker News)

...
...

Palo Alto Networks reported active exploitation of PAN-OS CVE-2026-0257 (CVSS 7.8), an authentication bypass affecting GlobalProtect portal and gateway components that can allow unauthorized VPN connections; limited exploitation was observed beginning May 17, 2026, with no post-access lateral movement identified. The report includes IoCs (IP addresses, hostnames, MACs), PoC client configuration values to search for in GlobalProtect logs, and notes CISA added the CVE to its KEV catalog with mitigation orders for federal agencies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.