INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Palo Alto VPN Exploit Vulnerability Active
| 2026-06-01 12:15 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
Cybercrimes have successfully exploited vulnerabilities in Palo Alto VPN systems, gaining unauthorized access to internet-facing security flaws. The attacks began as advisory exploits and escalated into active exploitation after researchers discovered the bugs. Cyber-crime actors bypassed GlobalProtect authentication override cookies on PAN-OS deployments using these vulnerabilities. This has led to more emergency patching for affected users, with Palo Alto customers being told to patch yet another internet-facing security flaw. Researchers at Rapid7 observed successful exploitation across multiple customer environments dating back to May 17 and validated the attack technique using proof-of-concept testing. The flaws affect PAN-OS deployments under specific configurations, making them vulnerable to unauthorized access without legitimate credentials.
Technical Mitigations AI-generated
• Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied.
• Fixes are available for supported releases, and the company advises patching to prevent exploitation.
• The flaw affects deployments using GlobalProtect authentication override cookies under specific configurations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-0300CVE-2026-0300
CVE-2026-0257CVE-2026-0257
Target & Sectors
Global Scope
Incident Timeline
May 18 and 21
Threat actors exploited a vulnerability in Palo Alto Networks' VPN software.
2026/05/02
Threat actors exploited a recently patched CVE in Palo Alto Networks' VPN product.
May 13
Palo Alto Networks disclosed the vulnerability on May 13, initially assigning it a medium-severity rating and later reassessing its severity to critical.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-0257
The company initially tagged
CVE-2026-0257
with a medium-severity rating when it
disclosed the defect
May 13, but quickly reassessed it as critical after Rapid7 observed and confirmed active exploitation in the wild.
May 17
Threat actors used a known vulnerability in Palo Alto Networks to exploit the VPN.
May 21
Threat actors exploited a vulnerability in Palo Alto Networks VPN software.
June 1
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-0257 to its Known Exploited Vulnerabilities catalog.
Click on any entity below to view its context and source!
attribution
Known Exploited
The flaw has now landed in CISA's Known Exploited Vulnerabilities catalog, with federal agencies given until June 1 to patch or otherwise secure affected systems.
Store it securely, and don’t reuse or share it with other users
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) Catalog, requiring federal civilian agencies to patch it by June 1.
tactic
T1588.006 - Vulnerabilities
The flaw has now landed in CISA's Known Exploited Vulnerabilities catalog, with federal agencies given until June 1 to patch or otherwise secure affected systems.
Store it securely, and don’t reuse or share it with other users
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) Catalog, requiring federal civilian agencies to patch it by June 1.
vulnerability
CVE-2026-0257
Store it securely, and don’t reuse or share it with other users
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) Catalog, requiring federal civilian agencies to patch it by June 1.
source_region
United States
Store it securely, and don’t reuse or share it with other users
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) Catalog, requiring federal civilian agencies to patch it by June 1.
attribution
CVE-2026
Store it securely, and don’t reuse or share it with other users
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) Catalog, requiring federal civilian agencies to patch it by June 1.
attribution
KEV
Store it securely, and don’t reuse or share it with other users
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) Catalog, requiring federal civilian agencies to patch it by June 1.
2026/06/01
Attackers exploited a previously unknown authentication bypass vulnerability in Palo Alto Networks' GlobalProtect VPN system, gaining unauthorized access to internal networks.
Click on any entity below to view its context and source!
organisation
IP
In some cases, cybercrims successfully obtained VPN IP addresses and network access, but the company said it didn’t observe evidence of successful lateral movement following initial access in the incidents it investigated.
“Rapid7 observed VPN IP assignment following the cookie authentication, granting them access to the internal network.
organisation
PAN
“Palo Alto Networks is actively monitoring limited exploitation attempts targeting CVE-2026-0257 on unpatched PAN-OS devices where mitigations have not been applied,” a company spokesperson said in a statement.
CVE-2026-0257 is an authentication bypass vulnerability in the GlobalProtect portal and gateway of Palo Alto Networks’ PAN-OS software.
Cyber-crime
Palo Alto VPN bug graduates from advisory to active exploitation
Rapid7: Attackers exploit authentication bypass flaw in the wild, meaning more emergency patching for PAN-OS users
Palo Alto customers are being been told to patch yet another internet-facing security flaw after researchers caught attackers bypassing GlobalProtect authentication and gaining unauthorized VPN access.
organisation
Palo Alto Networks
“Palo Alto Networks is actively monitoring limited exploitation attempts targeting CVE-2026-0257 on unpatched PAN-OS devices where mitigations have not been applied,” a company spokesperson said in a statement.
"Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied," the firm said in an update.
organisation
CVE-2026-0257
CVE-2026-0257 is an authentication bypass vulnerability in the GlobalProtect portal and gateway of Palo Alto Networks’ PAN-OS software.
organisation
GlobalProtect
CVE-2026-0257 is an authentication bypass vulnerability in the GlobalProtect portal and gateway of Palo Alto Networks’ PAN-OS software.
Cyber-crime
Palo Alto VPN bug graduates from advisory to active exploitation
Rapid7: Attackers exploit authentication bypass flaw in the wild, meaning more emergency patching for PAN-OS users
Palo Alto customers are being been told to patch yet another internet-facing security flaw after researchers caught attackers bypassing GlobalProtect authentication and gaining unauthorized VPN access.
The vulnerability has a few requisites that limit exposure, specifically posing risk to some Palo Alto Networks customers running GlobalProtect portal or gateway configured to enable authentication override cookies.
organisation
User-ID Authentication Portal
In May,
state-backed attackers were found exploiting CVE-2026-0300
, a critical remote code execution flaw in the PAN-OS User-ID Authentication Portal, before patches became widely available.
organisation
CyberScoop
Jake Knott, security researcher at watchTowr, told CyberScoop the vulnerability and resulting exploits follows a recurring trend wherein attackers target exposed network edge devices and rapidly identify, develop and weaponize exploits for initial access.
organisation
McKee
The attackers are “highly opportunistic and clearly monitor the security research community,” McKee said.
organisation
CVSS
The bug has a CVSS score of 7.8.
organisation
MDR
“Across multiple customers, Rapid7 observed successful exploitation via authentication probes using forged cookies, but the appliance accepted the cookie without a full VPN session being established in 8 out of 10 impacted MDR customers.”
GlobalProtect VPN users are urged to patch immediately.
organisation
GlobalProtect VPN
“Across multiple customers, Rapid7 observed successful exploitation via authentication probes using forged cookies, but the appliance accepted the cookie without a full VPN session being established in 8 out of 10 impacted MDR customers.”
GlobalProtect VPN users are urged to patch immediately.
Intelligence Sources
Infosecurity-Magazine
2026-06-01
Palo Alto Warns High-Severity Bug Is Being Actively Exploited
Infosecurity-Magazine
CyberScoop
2026-06-01
The Register - Cybercrime
2026-06-01
Palo Alto VPN bug graduates from advisory to active exploitation
The Register - Cybercrime
The Register - Cybercrime
2026-06-01
Palo Alto VPN bug graduates from advisory to active exploitation
The Register - Cybercrime
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-10T10:30
Comprehensive Tactical Telemetry
Highly Correlated Entities
12x
organisation
Identified Entity
IP
entity
6x
timeline
Temporal Reference
May 13
date
4x
attribution
Attributing Entity
Known Exploited
authority
3x
tactic
Cyber Operation Type
Lateral Movement
tactic
2x
vulnerability
Exploited CVE
CVE-2026-0257
cve
Contextual Telemetry
Context Block
4 METRICS
general metric
Cve-2026
300
cve-2026
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
source region
Origin Country
United States
country
vulnerability
CVSS Score
8
score
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.