# Palo Alto Networks Alerts to Active PAN-OS GlobalProtect Exploitation in the Wild
Palo Alto Networks disclosed Friday that attackers are actively exploiting CVE-2026-0257, a critical authentication bypass flaw in PAN-OS GlobalProtect VPN infrastructure, to gain unauthorized portal access. The company confirmed that unknown threat actors have weaponized the vulnerability in real-world attacks, marking the second major PAN-OS exploitation campaign within eighteen months. Organizations relying on GlobalProtect for remote access and VPN connectivity face immediate risk and should prioritize emergency patching and detection measures.
## The Threat
CVE-2026-0257 is an authentication bypass vulnerability residing in the portal and gateway authentication mechanisms of Palo Alto Networks PAN-OS. The flaw allows attackers to circumvent credential validation when accessing GlobalProtect portals without valid authentication, effectively granting them entry to enterprise VPN infrastructure. This attack vector requires network connectivity to the vulnerable GlobalProtect portal but no valid user credentials—a critical distinction that dramatically expands the pool of potential attackers from those with compromised employee accounts to any threat actor with internet access.
The vulnerability stems from improper session validation and insufficient authentication checks in the portal component. When an attacker sends specially crafted requests to the affected GlobalProtect portal, they can bypass authentication mechanisms and establish unauthenticated sessions that grant access to internal resources. Once inside the VPN tunnel, attackers gain the same network segmentation and access levels as legitimate remote employees, including access to file shares, internal applications, and potentially domain controllers and sensitive systems.
Palo Alto's threat intelligence team observed the initial exploitation activity in early June 2026, tracked to an unknown threat actor conducting what researchers describe as "limited targeted scanning." The activity suggests reconnaissance operations rather than mass exploitation, but the fact that attacks exist in the wild—coupled with public vulnerability details—means larger-scale abuse is likely imminent. Given that GlobalProtect VPN serves as the primary remote access mechanism for thousands of enterprises globally, particularly financial services, healthcare, technology, and government organizations, this vulnerability represents a significant risk to enterprise security posture.
## Severity and Impact
| Attribute | Details |
|-----------|---------|
| CVE ID | CVE-2026-0257 |
| CVSS v3.1 Score | 7.8 (High) |
| Vector String | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | None |
| User Interaction | None |
| CWE | CWE-287 (Improper Authentication) |
| Active Exploitation | Confirmed |
The 7.8 CVSS score reflects the flaw's critical nature: network-accessible, no authentication required, low complexity exploitation, and high impact across confidentiality, integrity, and availability. An attacker needs only to craft HTTP requests to the GlobalProtect portal endpoint—no special tools, no social engineering, no legitimate user account required. The low attack complexity means reliable, repeatable exploitation, and the confirmed active exploitation indicates threat actors have already validated working attack code.
## Affected Products
Palo Alto Networks PAN-OS versions affected by CVE-2026-0257 include:
Versions 10.0.0 through 10.1.14 (10.0 and 10.1 branches prior to patched releases)
Versions 11.0.0 through 11.0.3 (11.0 branch early releases)
Versions 11.1.0 through 11.1.2 (11.1 branch early releases)
Versions 12.0.0 through 12.0.1 (12.0 branch early releases)
Not Affected:
The vulnerability affects both physical firewalls (PA series) and virtual appliances (VM series) running vulnerable PAN-OS versions. Cloud-based Prisma Access deployments should consult Palo Alto's cloud security bulletins, as deployment architecture may affect exposure.
## Mitigations
Immediate Actions (Priority: Critical)
1. Apply Security Patches Immediately. Install PAN-OS versions 10.0.15, 11.0.4, 11.1.3, or 12.0.2 and later as applicable to your environment. Palo Alto released patches on June 13, 2026. Given active exploitation, patching should occur within 24–48 hours.
2. Deploy Network Segmentation. If immediate patching is impossible, restrict network access to GlobalProtect portals using firewall rules, network ACLs, or WAF rules to limit access to known legitimate IP ranges or organization-controlled networks. This is a temporary measure only and does not replace patching.
3. Enable Multi-Factor Authentication (MFA) on Portal Access. Require MFA for all GlobalProtect portal logins. This adds a second authentication factor that the vulnerability bypasses at the initial stage, reducing risk of complete account compromise.
4. Monitor and Hunt for Exploitation. Search PAN-OS logs for:
- Unauthenticated portal access attempts
- Failed authentication followed by successful sessions
- Anomalous traffic from GlobalProtect tunnels outside normal business hours
- Access to sensitive systems (domain controllers, file shares, databases) from VPN tunnels
5. Review VPN Access Logs. Identify any GlobalProtect sessions established in the past 30 days that lack corresponding successful authentication records. Investigate these sessions for lateral movement or data exfiltration.
Short-Term Mitigations (Days 3–7)
Long-Term Hardening
## References
---
## HackWire Analysis
The discovery of active exploitation of CVE-2026-0257 underscores a troubling pattern in enterprise security: vulnerability patches for high-impact remote access infrastructure are treated as routine updates rather than emergency incidents. Palo Alto Networks issued the fix on June 13, but the vulnerability's low attack complexity and zero-authentication requirement mean that organizations running unpatched GlobalProtect gateways have operated with an open front door for remote attackers since the flaw's introduction.
What's particularly alarming is the timing. GlobalProtect VPN is often the primary entry point for enterprise networks—the first line of defense that grants access to sensitive internal systems. Unlike web application vulnerabilities or endpoint software flaws that might sit in a network segment for months, a VPN authentication bypass is weaponized immediately because it directly enables lateral movement into sensitive infrastructure. The fact that Palo Alto confirmed real-world exploitation within days of initial disclosure suggests threat actors either developed the exploit independently or obtained it from early public information before patches became available.
The breach impact is amplified by the versions affected. PAN-OS 10.x and 11.x are still commonly deployed in production environments—many organizations run 10.1 or 11.0 because they delayed upgrades due to compatibility concerns or change management policies. This means the vulnerable population is likely in the thousands of enterprises. A sophisticated attacker with network access to a GlobalProtect portal can now gain VPN tunnel access without a valid employee account, eliminate the "attacker must know a credential" assumption, and pivot toward domain controllers, databases, and file servers within minutes.
Organizations should also consider supply chain implications. If an attacker gained access to a customer's network via this vulnerability, they may have accessed data, installed persistence mechanisms, or stolen credentials—activities that would remain undetected without forensic investigation. Palo Alto customers should assume that anyone accessing their GlobalProtect portals during the vulnerability window may have been a threat actor rather than a legitimate user.
The path forward is clear: treat this as an emergency, not a standard patch Tuesday. Customers unable to patch immediately should implement aggressive network segmentation and consider standing up a parallel VPN gateway running a patched version while rotating users to the secure infrastructure. The cost of 48 hours of downtime is negligible compared to the cost of a network compromise.
— HackWire Editorial
---
## Related Coverage