INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Palo Alto Warns of Active Exploitation of PAN-OS VPN Flaw

| 2026-06-15 11:11 HIGH HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
On June 15, 2026, Palo Alto Networks confirmed that attackers were actively exploiting CVE-2026-0257, a PAN-OS authentication bypass vulnerability affecting GlobalProtect portals and gateways. This allowed unauthorized users to bypass authentication and establish VPN connections without credentials. Rapid7 MDR identified successful exploitation across numerous customers on May 18 at 01:51 UTC, with the second wave hitting on May 21 from Dromatics Systems using a spoofed MAC address. The consistent use of this MAC address led Rapid7 to believe that a single threat actor was behind both campaigns. As of June 15, no indication of successful lateral movement had been observed from the devices affected by the exploitation.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-0257 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-0257CVE-2026-0257
Target & Sectors
Global Scope governmentgovernment
Incident Timeline
‎2026/06/15
Threat actors are actively exploiting CVE-2026-0257, a PAN-OS authentication bypass vulnerability affecting GlobalProtect portals and gateways.
infrastructure 7.8
infrastructure Linux
infrastructure Windows
infrastructure 10 bit endpoint
victims 10 impacted customers
infrastructure 23.128.228
infrastructure 104.207.144
infrastructure 146.19.216
infrastructure 179.43.172
infrastructure 185.195.232
infrastructure 198.12.106
infrastructure 202.144.192
Tactical Metrics
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
10
Bit Endpoint
Metrics
victims
10
Impacted Customers
Metrics
infrastructure
‎7.8
Software Version
Metrics
infrastructure
‎23.128.228
Software Version
Metrics
infrastructure
‎104.207.144
Software Version
Metrics
infrastructure
‎146.19.216
Software Version
Metrics
infrastructure
‎179.43.172
Software Version
Metrics
infrastructure
‎185.195.232
Software Version
Metrics
infrastructure
‎198.12.106
Software Version
Metrics
infrastructure
‎202.144.192
Software Version