{"id":231872,"date":"2026-06-15T02:17:00","date_gmt":"2026-06-15T06:17:00","guid":{"rendered":"https:\/\/testing.news-you-need.com\/index.php\/2026\/06\/15\/palo-alto-warns-of-active-exploitation-of-pan-os-globalprotect-vpn-flaw\/"},"modified":"2026-06-15T11:20:42","modified_gmt":"2026-06-15T15:20:42","slug":"palo-alto-warns-of-active-exploitation-of-pan-os-globalprotect-vpn-flaw","status":"publish","type":"post","link":"https:\/\/testing.news-you-need.com\/index.php\/2026\/06\/15\/palo-alto-warns-of-active-exploitation-of-pan-os-globalprotect-vpn-flaw\/","title":{"rendered":"Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/06\/palo-alto-warns-of-active-exploitation.html\">Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/06\/palo-alto-warns-of-active-exploitation.html\">https:\/\/thehackernews.com\/2026\/06\/palo-alto-warns-of-active-exploitation.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-06-15 02:17:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p>Author: <a href=\"\"><\/a><\/p>\n<p> Using an unordered list, summarize the following article with between 4 and 8 key points.<br \/>\n\ue804Ravie Lakshmanan\ue802Jun 15, 2026Vulnerability \/ VPN Security<br \/>\nPalo Alto Networks has revealed that it has observed &#8220;active exploitation&#8221; of a recently disclosed PAN-OS vulnerability by an unknown threat actor to obtain unauthorized access to GlobalProtect portals.<\/p>\n<p>The vulnerability in question is CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software that could be exploited by bad actors to set up VPN connections.<\/p>\n<p>According to the network security company, the security defect could be exploited by a bad actor to bypass security controls and initiate VPN connections.<\/p>\n<p>The vulnerability has been exploited in the wild in limited attacks, with initial activity observed on May 17, 2026. It&#8217;s currently unknown who is behind the exploitation efforts.<\/p>\n<p>&#8220;No post-access behavior or lateral movement has been identified as of this time,&#8221; Palo Alto Networks said. &#8220;Only a small portion of the probed devices actually established VPN sessions, resulting in gateway-connected events.&#8221;<\/p>\n<p>The company has also released indicators of compromise (IoCs) associated with the activity &#8211;<\/p>\n<p>    IP addresses &#8211;<\/p>\n<p>      23.128.228[.]6<br \/>\n      104.207.144[.]154<br \/>\n      146.19.216[.]119<br \/>\n      146.19.216[.]120<br \/>\n      146.19.216[.]125<br \/>\n      179.43.172[.]213<br \/>\n      185.195.232[.]139<br \/>\n      198.12.106[.]60<br \/>\n      202.144.192[.]47<\/p>\n<p>    Host Names and MAC Addresses &#8211;<\/p>\n<p>      aa:bb:cc:dd:ee:ff<br \/>\n      00:11:22:33:44:55<br \/>\n      WINDOWS-LAPTOP-001<br \/>\n      DESKTOP-GP01<br \/>\n      GP-CLIENT<\/p>\n<p>Palo Alto Networks is also urging customers to search GlobalProtect logs for successful gateway-connected events that match the following hard-coded client configuration values from a proof-of-concept (PoC) exploit &#8211;<\/p>\n<p>  endpoint_os_version : Microsoft Windows 10 Pro 64-bit<br \/>\n  source_user_info.domain : empty<\/p>\n<p>Late last month, the U.S. Cybersecurity and Infrastructure Security Agency (CSIA) added CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) catalog, ordering Federal Civilian Executive Branch (FCEB) agencies to mitigate the flaw by June 1, 2026.<\/p>\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw https:\/\/thehackernews.com\/2026\/06\/palo-alto-warns-of-active-exploitation.html Publish Date: 2026-06-15&#8230;<\/p>\n","protected":false},"author":1,"featured_media":231874,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiMFIs6j0CgFzSojDqSi_UsqRzjlbYcRsrJG714Yh40TZXU4ZzlB_Do-7nbx5WGGvOS7mV3TojQLTiHbFS57BtgCo4hlF0DebzDtrSh5YzXkqNhjEI4JG97N_vpkFzeJP3V-adbSsPYRdYCQklFdweodtTJHywVHA5HiqgvYOp5eyxW0aQxKVacua9F9w3_\/s1600\/paloalto-vpn.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[24,31,29,34,27],"class_list":["post-231872","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-exploit","tag-network-security","tag-threat-actor","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/231872"}],"collection":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=231872"}],"version-history":[{"count":1,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/231872\/revisions"}],"predecessor-version":[{"id":231876,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/231872\/revisions\/231876"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/231874"}],"wp:attachment":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=231872"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=231872"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=231872"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}