Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
DuckDNS abused to distribute VBS/PowerShell RATs
August 10, 2026
AiTM Phishing Hijacks Microsoft 365 Sessions, Targets Payroll Emails
August 10, 2026
Critical Flaws in Connective eID Extension Expose Belgian ID PINs, Allow RCE
August 10, 2026
Home/CyberSecurity News/Palo Alto Networks Patches Critical GlobalProtect VPN Vulnerability CVE-2024-34000
CyberSecurity News

Palo Alto Networks Patches Critical GlobalProtect VPN Vulnerability CVE-2024-34000

Key Takeaways A critical authentication bypass vulnerability (CVE-2026-0257) in Palo Alto Networks PAN-OS GlobalProtect has been actively exploited in the wild. The flaw allows unauthenticated...

Emy Elsamnoudy
Emy Elsamnoudy
June 15, 2026 3 Min Read
56 0

Key Takeaways

  • A critical authentication bypass vulnerability (CVE-2026-0257) in Palo Alto Networks PAN-OS GlobalProtect has been actively exploited in the wild.
  • The flaw allows unauthenticated attackers to establish unauthorized VPN connections without credentials.
  • CISA added CVE-2026-0257 to its KEV catalog on May 29, 2026, confirming its severity and active exploitation.
  • Organizations using GlobalProtect are urged to immediately apply patches or workarounds and hunt for Indicators of Compromise (IOCs).

Palo Alto Networks GlobalProtect Flaw Under Active Attack

Palo Alto Networks’ Unit 42 has issued an urgent advisory concerning active exploitation of a critical authentication bypass vulnerability, identified as CVE-2026-0257. This severe flaw impacts the GlobalProtect portal and gateway components of PAN-OS software, allowing unauthenticated remote attackers to circumvent security measures and initiate unauthorized VPN connections without providing any credentials.

Table Of Content

  • Key Takeaways
  • Palo Alto Networks GlobalProtect Flaw Under Active Attack
  • Exploitation Details and Observations
  • Indicators of Compromise (IOCs)
  • IP Address Indicators
  • Host-Based Indicators
  • Post-PoC Hard-Coded Client Configuration Indicators
  • What You Should Do

The severity of CVE-2026-0257 was underscored on May 29, 2026, when the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities (KEV) catalog. This addition confirms that the vulnerability is being actively leveraged in real-world attacks.

Exploitation Details and Observations

Researchers at Unit 42 have observed an unidentified threat actor actively probing devices running GlobalProtect. While a wide range of targets were scanned, only a smaller subset successfully established VPN sessions, leading to “gateway-connected” events. As of this reporting, there is no confirmed evidence of post-access malicious activity, such as lateral movement or data exfiltration, but the window for such actions remains open.

Organizations are strongly advised to conduct immediate threat hunting for specific Indicators of Compromise (IOCs) within their GlobalProtect logs. Any successful gateway-connected events matching these indicators should trigger immediate incident response protocols.

For detailed technical analysis of the observed exploitation activity, Rapid7 has also published its findings. Defenders should also consult the official Palo Alto Networks security advisory for comprehensive information on the vulnerability, available workarounds, and instructions for upgrading to patched PAN-OS versions.

Indicators of Compromise (IOCs)

Threat hunters should specifically search GlobalProtect logs for successful login connections originating from the following IP addresses. This activity is particularly critical if it predates May 29, 2026, the date of the public Proof-of-Concept (PoC) release.

IP Address Indicators

IP Address Context Phase
23.128.228[.]6 Malicious source IP Pre-PoC (before May 29, 2026)
104.207.144[.]154 Malicious source IP Pre-PoC (before May 29, 2026)
146.19.216[.]119 Malicious source IP Pre-PoC (before May 29, 2026)
146.19.216[.]120 Malicious source IP Pre-PoC (before May 29, 2026)
146.19.216[.]125 Malicious source IP Pre-PoC (before May 29, 2026)
179.43.172[.]213 Malicious source IP Pre-PoC (before May 29, 2026)
185.195.232[.]139 Malicious source IP Pre-PoC (before May 29, 2026)
198.12.106[.]60 Malicious source IP Pre-PoC (before May 29, 2026)
202.144.192[.]47 Malicious source IP Pre-PoC (before May 29, 2026)

Host-Based Indicators

Indicator Type Context
aa:bb:cc:dd:ee:ff MAC Address Suspicious device identifier in GlobalProtect logs
00:11:22:33:44:55 MAC Address Suspicious device identifier in GlobalProtect logs
WINDOWS-LAPTOP-001 Hostname Suspicious host ID in GlobalProtect logs
DESKTOP-GP01 Hostname Suspicious host ID in GlobalProtect logs
GP-CLIENT Hostname Suspicious host ID in GlobalProtect logs

Post-PoC Hard-Coded Client Configuration Indicators

Field Value Context
endpoint_os_version Microsoft Windows 10 Pro 64-bit Hard-coded in PoC exploit code
source_user_info.domain (empty) Hard-coded in PoC exploit code

What You Should Do

  • Patch Immediately: Apply all available security updates and patches from Palo Alto Networks for your PAN-OS GlobalProtect deployments.
  • Implement Workarounds: If immediate patching is not feasible, implement recommended workarounds detailed in the official Palo Alto Networks security advisory.
  • Hunt for IOCs: Proactively search your GlobalProtect logs for any signs of the listed IP addresses, MAC addresses, hostnames, or client configuration indicators. Pay close attention to activity before May 29, 2026.
  • Activate Incident Response: For any confirmed hits on the IOCs, activate your organization’s incident response plan immediately to investigate and mitigate potential breaches.
  • Monitor Network Traffic: Continuously monitor network traffic for unusual activity originating from or destined for your GlobalProtect gateways.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVECybersecurityExploitPatchSecurityThreatVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

152 Malicious Chrome Extensions Track Users and Fake Google Search Traffic

Next Post

Unlocked PHP Installation Page Exposes Threat Actor Malware Platform

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical WordPress Supply Chain Attack Compromises Themes via Poisoned API Response
August 10, 2026
Anthropic Claude Opus 5 Reduces Indirect Prompt Injection Attacks to 2%
August 10, 2026
OpenClaw AI Agent Exploits Gym API to Steal Workout Slot
August 10, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us