INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Palo Alto Warns of Active Exploitation of PAN-OS VPN Flaw
| 2026-06-15 11:11 HIGH HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
On June 15, 2026, Palo Alto Networks confirmed that attackers were actively exploiting CVE-2026-0257, a PAN-OS authentication bypass vulnerability affecting GlobalProtect portals and gateways. This allowed unauthorized users to bypass authentication and establish VPN connections without credentials. Rapid7 MDR identified successful exploitation across numerous customers on May 18 at 01:51 UTC, with the second wave hitting on May 21 from Dromatics Systems using a spoofed MAC address. The consistent use of this MAC address led Rapid7 to believe that a single threat actor was behind both campaigns. As of June 15, no indication of successful lateral movement had been observed from the devices affected by the exploitation.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-0257 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-0257CVE-2026-0257
Target & Sectors
Global Scope
governmentgovernment
Incident Timeline
2026/06/15
Threat actors are actively exploiting CVE-2026-0257, a PAN-OS authentication bypass vulnerability affecting GlobalProtect portals and gateways.
Click on any entity below to view its context and source!
infrastructure
7.8
The vulnerability in question is
CVE-2026-0257
(CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software that could be exploited by bad actors to set up VPN connections.
infrastructure
Linux
The logs showed cookie-based authentication to the local admin account across several customer environments, using the hostname “GP-CLIENT” on a Linux system and a spoofed MAC address of aa:bb:cc:dd:ee:ff.
infrastructure
Windows
….232[.]139
198.12.106[.]60
202.144.192[.]47
Host Names and MAC Addresses –
aa:bb:cc:dd:ee:ff
00:11:22:33:44:55
WINDOWS-LAPTOP-001
DESKTOP-GP01
GP-CLIENT
Palo Alto Networks is advising customers to review GlobalProtect logs…
In particular, they should look for sessions where the client configuration shows a Windows 10 Pro 64-bit endpoint and an empty domain field for the source user, as these values may indicate potential exploitation attempts or anomalous connections…
…198.12.106[.]60
202.144.192[.]47
Host Names and MAC Addresses -
aa:bb:cc:dd:ee:ff
00:11:22:33:44:55
WINDOWS-LAPTOP-001
DESKTOP-GP01
GP-CLIENT
Palo Alto Networks is also urging customers to search GlobalProtect lo…
infrastructure
10 bit endpoint
In particular, they should look for sessions where the client configuration shows a Windows 10 Pro 64-bit endpoint and an empty domain field for the source user, as these values may indicate potential exploitation attempts or anomalous connections c…
"
The company has also released indicators of compromise (IoCs) associated with the activity -
IP addresses -
23.128.228[.]6
104.207.144[.]154
146.19.216[.]119
146.19.216[.]120
146.19.216[.]125
179.43.172[.]213
185.195.…
victims
10 impacted customers
“The earliest date for observed exploitation was May 17, 2026”
In 8 out of 10 impacted customers, however, the appliance accepted the forged cookie without establishing a full VPN session.
infrastructure
23.128.228
…The company has also released indicators of compromise (IoCs) associated with the activity -
IP addresses -
23.128.228[.]6
104.207.144[.]154
146.19.216[.]119
146.19.216[.]120
146.19.216[.]125
179.43.172[.]213
185.195.232…
infrastructure
104.207.144
…lso released indicators of compromise (IoCs) associated with the activity -
IP addresses -
23.128.228[.]6
104.207.144[.]154
146.19.216[.]119
146.19.216[.]120
146.19.216[.]125
179.43.172[.]213
185.195.232[.]139
198.12.1…
infrastructure
146.19.216
…ors of compromise (IoCs) associated with the activity -
IP addresses -
23.128.228[.]6
104.207.144[.]154
146.19.216[.]119
146.19.216[.]120
146.19.216[.]125
179.43.172[.]213
185.195.232[.]139
198.12.106[.]60
202.144.19…
infrastructure
179.43.172
…IP addresses -
23.128.228[.]6
104.207.144[.]154
146.19.216[.]119
146.19.216[.]120
146.19.216[.]125
179.43.172[.]213
185.195.232[.]139
198.12.106[.]60
202.144.192[.]47
Host Names and MAC Addresses -
a…
infrastructure
185.195.232
…s -
23.128.228[.]6
104.207.144[.]154
146.19.216[.]119
146.19.216[.]120
146.19.216[.]125
179.43.172[.]213
185.195.232[.]139
198.12.106[.]60
202.144.192[.]47
Host Names and MAC Addresses -
aa:bb:cc:dd:ee:ff…
infrastructure
198.12.106
…8[.]6
104.207.144[.]154
146.19.216[.]119
146.19.216[.]120
146.19.216[.]125
179.43.172[.]213
185.195.232[.]139
198.12.106[.]60
202.144.192[.]47
Host Names and MAC Addresses -
aa:bb:cc:dd:ee:ff
00:11:22:33:44:55…
infrastructure
202.144.192
…4[.]154
146.19.216[.]119
146.19.216[.]120
146.19.216[.]125
179.43.172[.]213
185.195.232[.]139
198.12.106[.]60
202.144.192[.]47
Host Names and MAC Addresses -
aa:bb:cc:dd:ee:ff
00:11:22:33:44:55
WINDOWS-LAPTOP-001…
Tactical Metrics
Metrics
infrastructure
Linux
Affected Product
Click for context!
The logs showed cookie-based authentication to the local admin account across several customer environments, using the hostname “GP-CLIENT” on a Linux system and a spoofed MAC address of aa:bb:cc:dd:ee:ff.
Metrics
infrastructure
Windows
Affected Product
….232[.]139
198.12.106[.]60
202.144.192[.]47
Host Names and MAC Addresses –
aa:bb:cc:dd:ee:ff
00:11:22:33:44:55
WINDOWS-LAPTOP-001
DESKTOP-GP01
GP-CLIENT
Palo Alto Networks is advising customers to review GlobalProtect logs…
In particular, they should look for sessions where the client configuration shows a Windows 10 Pro 64-bit endpoint and an empty domain field for the source user, as these values may indicate potential exploitation attempts or anomalous connections…
…198.12.106[.]60
202.144.192[.]47
Host Names and MAC Addresses -
aa:bb:cc:dd:ee:ff
00:11:22:33:44:55
WINDOWS-LAPTOP-001
DESKTOP-GP01
GP-CLIENT
Palo Alto Networks is also urging customers to search GlobalProtect lo…
Metrics
infrastructure
10
Bit Endpoint
In particular, they should look for sessions where the client configuration shows a Windows 10 Pro 64-bit endpoint and an empty domain field for the source user, as these values may indicate potential exploitation attempts or anomalous connections c…
"
The company has also released indicators of compromise (IoCs) associated with the activity -
IP addresses -
23.128.228[.]6
104.207.144[.]154
146.19.216[.]119
146.19.216[.]120
146.19.216[.]125
179.43.172[.]213
185.195.…
Metrics
victims
10
Impacted Customers
“The earliest date for observed exploitation was May 17, 2026”
In 8 out of 10 impacted customers, however, the appliance accepted the forged cookie without establishing a full VPN session.
Metrics
infrastructure
7.8
Software Version
The vulnerability in question is
CVE-2026-0257
(CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software that could be exploited by bad actors to set up VPN connections.
Metrics
infrastructure
23.128.228
Software Version
…The company has also released indicators of compromise (IoCs) associated with the activity -
IP addresses -
23.128.228[.]6
104.207.144[.]154
146.19.216[.]119
146.19.216[.]120
146.19.216[.]125
179.43.172[.]213
185.195.232…
Metrics
infrastructure
104.207.144
Software Version
…lso released indicators of compromise (IoCs) associated with the activity -
IP addresses -
23.128.228[.]6
104.207.144[.]154
146.19.216[.]119
146.19.216[.]120
146.19.216[.]125
179.43.172[.]213
185.195.232[.]139
198.12.1…
Metrics
infrastructure
146.19.216
Software Version
…ors of compromise (IoCs) associated with the activity -
IP addresses -
23.128.228[.]6
104.207.144[.]154
146.19.216[.]119
146.19.216[.]120
146.19.216[.]125
179.43.172[.]213
185.195.232[.]139
198.12.106[.]60
202.144.19…
Metrics
infrastructure
179.43.172
Software Version
…IP addresses -
23.128.228[.]6
104.207.144[.]154
146.19.216[.]119
146.19.216[.]120
146.19.216[.]125
179.43.172[.]213
185.195.232[.]139
198.12.106[.]60
202.144.192[.]47
Host Names and MAC Addresses -
a…
Metrics
infrastructure
185.195.232
Software Version
…s -
23.128.228[.]6
104.207.144[.]154
146.19.216[.]119
146.19.216[.]120
146.19.216[.]125
179.43.172[.]213
185.195.232[.]139
198.12.106[.]60
202.144.192[.]47
Host Names and MAC Addresses -
aa:bb:cc:dd:ee:ff…
Metrics
infrastructure
198.12.106
Software Version
…8[.]6
104.207.144[.]154
146.19.216[.]119
146.19.216[.]120
146.19.216[.]125
179.43.172[.]213
185.195.232[.]139
198.12.106[.]60
202.144.192[.]47
Host Names and MAC Addresses -
aa:bb:cc:dd:ee:ff
00:11:22:33:44:55…
Metrics
infrastructure
202.144.192
Software Version
…4[.]154
146.19.216[.]119
146.19.216[.]120
146.19.216[.]125
179.43.172[.]213
185.195.232[.]139
198.12.106[.]60
202.144.192[.]47
Host Names and MAC Addresses -
aa:bb:cc:dd:ee:ff
00:11:22:33:44:55
WINDOWS-LAPTOP-001…
Intelligence Sources
The Hacker News
2026-06-15
Security Affairs
2026-06-15
Security Affairs
2026-06-01
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T12:27
Comprehensive Tactical Telemetry
Highly Correlated Entities
21x
organisation
Identified Entity
PAN
entity
13x
attribution
Attributing Entity
the U.S. Cybersecurity and Infrastructure Security Agency
authority
10x
timeline
Temporal Reference
May 17, 2026
date
8x
infrastructure
Software Version
7.8
version
2x
tactic
MITRE ATT&CK Technique
T1588.005 - Exploits
technique
2x
infrastructure
Affected Product
Linux
software
2x
general metric
Jun
15
jun
Contextual Telemetry
Context Block
8 METRICS
tactic
Cyber Operation Type
Lateral Movement
tactic
vulnerability
Exploited CVE
CVE-2026-0257
cve
general metric
Cve-2026
257
cve-2026
infrastructure
Bit Endpoint
10
bit endpoint
general metric
Bit
64
bit
victims
Impacted Customers
10
impacted customers
general metric
Score
8
score
vulnerability
CVSS Score
8
score
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.