INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Palo Alto VPN Exploit Vulnerability Active

| 2026-06-01 12:15 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
Cybercrimes have successfully exploited vulnerabilities in Palo Alto VPN systems, gaining unauthorized access to internet-facing security flaws. The attacks began as advisory exploits and escalated into active exploitation after researchers discovered the bugs. Cyber-crime actors bypassed GlobalProtect authentication override cookies on PAN-OS deployments using these vulnerabilities. This has led to more emergency patching for affected users, with Palo Alto customers being told to patch yet another internet-facing security flaw. Researchers at Rapid7 observed successful exploitation across multiple customer environments dating back to May 17 and validated the attack technique using proof-of-concept testing. The flaws affect PAN-OS deployments under specific configurations, making them vulnerable to unauthorized access without legitimate credentials.
Technical Mitigations AI-generated
• Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied. • Fixes are available for supported releases, and the company advises patching to prevent exploitation. • The flaw affects deployments using GlobalProtect authentication override cookies under specific configurations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-0300CVE-2026-0300 CVE-2026-0257CVE-2026-0257
Target & Sectors
Global Scope
Incident Timeline
‎May 18 and 21
Threat actors exploited a vulnerability in Palo Alto Networks' VPN software.
‎2026/05/02
Threat actors exploited a recently patched CVE in Palo Alto Networks' VPN product.
‎May 13
Palo Alto Networks disclosed the vulnerability on May 13, initially assigning it a medium-severity rating and later reassessing its severity to critical.
vulnerability CVE-2026-0257
‎May 17
Threat actors used a known vulnerability in Palo Alto Networks to exploit the VPN.
‎May 21
Threat actors exploited a vulnerability in Palo Alto Networks VPN software.
‎June 1
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-0257 to its Known Exploited Vulnerabilities catalog.
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
vulnerability CVE-2026-0257
source_region United States
attribution CVE-2026
attribution KEV
‎2026/06/01
Attackers exploited a previously unknown authentication bypass vulnerability in Palo Alto Networks' GlobalProtect VPN system, gaining unauthorized access to internal networks.
organisation IP
organisation PAN
organisation Palo Alto Networks
organisation CVE-2026-0257
organisation GlobalProtect
organisation User-ID Authentication Portal
organisation CyberScoop
organisation McKee
organisation CVSS
organisation MDR
organisation GlobalProtect VPN
Intelligence Sources
Infosecurity-Magazine 2026-06-01
The Register - Cybercrime 2026-06-01
The Register - Cybercrime 2026-06-01