Palo Alto Networks Patches Critical GlobalProtect VPN Vulnerability CVE-2024-34000
Key Takeaways A critical authentication bypass vulnerability (CVE-2026-0257) in Palo Alto Networks PAN-OS GlobalProtect has been actively exploited in the wild. The flaw allows unauthenticated...
Key Takeaways
- A critical authentication bypass vulnerability (CVE-2026-0257) in Palo Alto Networks PAN-OS GlobalProtect has been actively exploited in the wild.
- The flaw allows unauthenticated attackers to establish unauthorized VPN connections without credentials.
- CISA added CVE-2026-0257 to its KEV catalog on May 29, 2026, confirming its severity and active exploitation.
- Organizations using GlobalProtect are urged to immediately apply patches or workarounds and hunt for Indicators of Compromise (IOCs).
Palo Alto Networks GlobalProtect Flaw Under Active Attack
Palo Alto Networks’ Unit 42 has issued an urgent advisory concerning active exploitation of a critical authentication bypass vulnerability, identified as CVE-2026-0257. This severe flaw impacts the GlobalProtect portal and gateway components of PAN-OS software, allowing unauthenticated remote attackers to circumvent security measures and initiate unauthorized VPN connections without providing any credentials.
Table Of Content
The severity of CVE-2026-0257 was underscored on May 29, 2026, when the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities (KEV) catalog. This addition confirms that the vulnerability is being actively leveraged in real-world attacks.
Exploitation Details and Observations
Researchers at Unit 42 have observed an unidentified threat actor actively probing devices running GlobalProtect. While a wide range of targets were scanned, only a smaller subset successfully established VPN sessions, leading to “gateway-connected” events. As of this reporting, there is no confirmed evidence of post-access malicious activity, such as lateral movement or data exfiltration, but the window for such actions remains open.
Organizations are strongly advised to conduct immediate threat hunting for specific Indicators of Compromise (IOCs) within their GlobalProtect logs. Any successful gateway-connected events matching these indicators should trigger immediate incident response protocols.
For detailed technical analysis of the observed exploitation activity, Rapid7 has also published its findings. Defenders should also consult the official Palo Alto Networks security advisory for comprehensive information on the vulnerability, available workarounds, and instructions for upgrading to patched PAN-OS versions.
Indicators of Compromise (IOCs)
Threat hunters should specifically search GlobalProtect logs for successful login connections originating from the following IP addresses. This activity is particularly critical if it predates May 29, 2026, the date of the public Proof-of-Concept (PoC) release.
IP Address Indicators
| IP Address | Context | Phase |
|---|---|---|
| 23.128.228[.]6 | Malicious source IP | Pre-PoC (before May 29, 2026) |
| 104.207.144[.]154 | Malicious source IP | Pre-PoC (before May 29, 2026) |
| 146.19.216[.]119 | Malicious source IP | Pre-PoC (before May 29, 2026) |
| 146.19.216[.]120 | Malicious source IP | Pre-PoC (before May 29, 2026) |
| 146.19.216[.]125 | Malicious source IP | Pre-PoC (before May 29, 2026) |
| 179.43.172[.]213 | Malicious source IP | Pre-PoC (before May 29, 2026) |
| 185.195.232[.]139 | Malicious source IP | Pre-PoC (before May 29, 2026) |
| 198.12.106[.]60 | Malicious source IP | Pre-PoC (before May 29, 2026) |
| 202.144.192[.]47 | Malicious source IP | Pre-PoC (before May 29, 2026) |
Host-Based Indicators
| Indicator | Type | Context |
|---|---|---|
| aa:bb:cc:dd:ee:ff | MAC Address | Suspicious device identifier in GlobalProtect logs |
| 00:11:22:33:44:55 | MAC Address | Suspicious device identifier in GlobalProtect logs |
| WINDOWS-LAPTOP-001 | Hostname | Suspicious host ID in GlobalProtect logs |
| DESKTOP-GP01 | Hostname | Suspicious host ID in GlobalProtect logs |
| GP-CLIENT | Hostname | Suspicious host ID in GlobalProtect logs |
Post-PoC Hard-Coded Client Configuration Indicators
| Field | Value | Context |
|---|---|---|
| endpoint_os_version | Microsoft Windows 10 Pro 64-bit | Hard-coded in PoC exploit code |
| source_user_info.domain | (empty) | Hard-coded in PoC exploit code |
What You Should Do
- Patch Immediately: Apply all available security updates and patches from Palo Alto Networks for your PAN-OS GlobalProtect deployments.
- Implement Workarounds: If immediate patching is not feasible, implement recommended workarounds detailed in the official Palo Alto Networks security advisory.
- Hunt for IOCs: Proactively search your GlobalProtect logs for any signs of the listed IP addresses, MAC addresses, hostnames, or client configuration indicators. Pay close attention to activity before May 29, 2026.
- Activate Incident Response: For any confirmed hits on the IOCs, activate your organization’s incident response plan immediately to investigate and mitigate potential breaches.
- Monitor Network Traffic: Continuously monitor network traffic for unusual activity originating from or destined for your GlobalProtect gateways.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.