Cyber Cookie mascotCyber Cookie
Menu ▾
CVE-2026-0257
highCVSS 7.8

Palo Alto PAN-OS GlobalProtect (actively exploited)

PAN-OS is the operating system running Palo Alto Networks firewalls and network security appliances — the software layer that decides what traffic enters and leaves an organisation's network.

Reported in Issue #8Trusted WordPress Plugins Were Planting Back Doors

Root Cause

GlobalProtect's portal and gateway components fail to properly verify incoming connection requests. The validation step that should confirm a user is who they claim to be can be bypassed entirely, allowing an attacker to proceed as an authenticated user without ever supplying legitimate credentials.

Attack Vector

An attacker sends a crafted request to the GlobalProtect portal or gateway. The system accepts it without completing proper authentication and establishes a VPN session. Palo Alto confirmed that only a fraction of probed devices completed full sessions, but those that did registered as gateway-connected events, placing the attacker inside the network perimeter. No post-access lateral movement (the act of moving from one internal system to another after gaining initial entry) has been identified yet, but the window for it remains open on unpatched devices.

Detection Notes

  1. Audit GlobalProtect gateway logs for VPN sessions from unrecognised source IP addresses, particularly from mid-May 2026 onwards.
  2. Look for gateway-connected events with no corresponding legitimate user login record.
  3. Flag any unusual admin activity or new account creation following suspicious VPN sessions.

Recommended Actions

  1. Apply Palo Alto's current PAN-OS patch immediately. This is actively exploited.
  2. Where operationally possible, restrict GlobalProtect portal access to known, approved IP ranges.
  3. Review all VPN session logs from mid-May onwards and investigate anything anomalous before clearing it.