What it is
GHSA-JQXW-84HX-6QJ5 is an unauthenticated vulnerability tracked by Previdian. Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to...
Vulnerability report
Linked CVE: CVE-2026-0257
Authentication Bypass
affected before *
Decision summary
Direct answers before the deeper technical record.
What it is
GHSA-JQXW-84HX-6QJ5 is an unauthenticated vulnerability tracked by Previdian. Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to...
Is it exploited?
Yes. Previdian sensors observed exploitation attempts with confirmed confidence. Listed in CISA KEV. Also confirmed by third-party sources.
Who is affected?
Affected versions: affected before *.
What should we do?
Patch immediately, validate internet-facing exposure, and monitor for matching requests.
Overview
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.
Panorama and Cloud NGFW are not impacted by these issues.
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
CVE
A trusted third party reported exploitation.
Previdian sensor
Previdian first observed exploitation attempts targeting this vulnerability in our honeypot sensors.
CVE
Malware families have been linked to exploitation of this CVE.
GitHub
Public scanner or PoC coverage increases practical exploitability.
Per-source evidence links for KEV attestations are available through the Previdian Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| The Shadowserver First | 2026-05-30 07:34 UTC |
| BleepingComputer | 2026-05-30 18:02 UTC |
| CVE | 2026-06-01 10:28 UTC |
| CISA | 2026-06-02 14:00 UTC |
| TheHackerNews | 2026-06-02 14:21 UTC |
| All CISA Advisories | 2026-06-02 14:21 UTC |
| Palo Alto Unit42 | 2026-06-05 14:20 UTC |
Operational indicators for this CVE are listed under Detection.
Sensor telemetry
Previdian sensors recorded exploitation attempts targeting this vulnerability. The cards and chart show volume, unique attackers, and daily activity.
11
Attempts observed
3
Unique attacker IPs
3
Attacker countries
DE · NL · US
9
Sensors observed
GHSA-JQXW-84HX-6QJ5 exploitation attempts over the last 20 days
Daily events observed by Previdian sensors
Updated 23 Sep 2026
First observed 23 Jun 2026 · Last observed 21 Sep 2026
Pro adds sensor region and window summaries. Enterprise adds raw IPs, paths, User-Agents, and payloads.
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Request targets and User-Agents available in Pro. Callback host details available in Enterprise.
Nuclei template detected 03 Jun 2026.
View Nuclei template (opens in new tab)No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →Operational indicators linked to exploitation of this CVE. IoCs age over time — especially IP addresses.
| Type | Indicator | First Seen | Last Seen | Age | Source |
|---|---|---|---|---|---|
| IP Stale |
23.128.228.6
|
2026-06-05 17:24 UTC | 2026-06-05 17:24 UTC | 4 months ago | Source |
| IP Stale |
104.207.144.154
|
2026-06-05 17:24 UTC | 2026-06-05 17:24 UTC | 4 months ago | Source |
| IP Stale |
146.19.216.119
|
2026-06-05 17:24 UTC | 2026-06-05 17:24 UTC | 4 months ago | Source |
| IP Stale |
146.19.216.120
|
2026-06-05 17:24 UTC | 2026-06-05 17:24 UTC | 4 months ago | Source |
| IP Stale |
146.19.216.125
|
2026-06-05 17:24 UTC | 2026-06-05 17:24 UTC | 4 months ago | Source |
| IP Stale |
179.43.172.213
|
2026-06-05 17:24 UTC | 2026-06-05 17:24 UTC | 4 months ago | Source |
| IP Stale |
185.195.232.139
|
2026-06-05 17:24 UTC | 2026-06-05 17:24 UTC | 4 months ago | Source |
| IP Stale |
198.12.106.60
|
2026-06-05 17:24 UTC | 2026-06-05 17:24 UTC | 4 months ago | Source |
| IP Stale |
202.144.192.47
|
2026-06-05 17:24 UTC | 2026-06-05 17:24 UTC | 4 months ago | Source |
Scanner and exploit-framework references linked to this CVE.
| Scanner | Reference | Detected |
|---|---|---|
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/javascript/cves/2026/CVE-2026-0257.yaml | 03 Jun 2026 |
| Nessus | https://www.tenable.com/plugins/nessus/314450 | 14 May 2026 |
Risk and context
CVSS v4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:Amber
EPSS
93.9%
Recent mention · DarkWebInformer
CVE-2026-0257 is an authentication bypass in the GlobalProtect portal and gateway components of Palo Alto Networks PAN-OS software.
Read full advisoryCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:D/RE:M/U:Amber
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Recent mention · DarkWebInformer
Trusting a Cookie It Never Issued: The PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257)DarkWebInformer · 21 Jul 2026
CVE-2026-0257 is an authentication bypass in the GlobalProtect portal and gateway components of Palo Alto Networks PAN-OS software.
Recent mention · TheHackerNews
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial AccessTheHackerNews · 21 Jul 2026
Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway
Recent mention · Daily CyberSecurity
Qilin Ransomware Deployed via Palo Alto GlobalProtect Flaw CVE-2026-0257Daily CyberSecurity · 21 Jul 2026
During June 2026, Arctic Wolf Labs traced several ransomware intrusions to one entry point. Attackers exploited a Palo The post Qilin Ransomware Deployed via Palo Alto GlobalProtect Flaw CVE-2026-0257 appeared first on Daily CyberSecurity.
Recent mention · TheHackerNews
Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN FlawTheHackerNews · 15 Jun 2026
Palo Alto Networks has revealed that it has observed "active exploitation" of a recently disclosed PAN-OS vulnerability by an unknown threat actor to obtain unauthorized access to GlobalProtect portals. The vulnerability in question is CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software that could be exploited by bad
Recent mention · Palo Alto Unit42
Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257Palo Alto Unit42 · 05 Jun 2026
We include indicators of activity and mitigations for PAN-OS vulnerability CVE-2026-0257. The post Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 appeared first on Unit 42.
Recent mention · BleepingComputer
Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacksBleepingComputer · 30 May 2026
Palo Alto Networks is warning that hackers are now exploiting a PAN-OS GlobalProtect authentication bypass flaw, tracked as CVE-2026-0257, in attacks attempting to breach corporate networks. [...]
Recent mention · TheHackerNews
PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active ExploitationTheHackerNews · 30 May 2026
Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-0257 (CVSS score: 7.8), refers to a case of authentication bypass that could be exploited by bad actors to set up VPN connections. "Authentication bypass vulnerabilities in the
Recent mention · Palo Alto Networks Security Advisories
CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities (Severity: HIGH)Palo Alto Networks Security Advisories · 29 May 2026
Recent mention · All CISA Advisories
CISA Adds One Known Exploited Vulnerability to CatalogAll CISA Advisories · 29 May 2026
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-0257 Palo Alto Networks PAN-OS Authentication Bypass Vulnerability This type of vulnerability is a frequent attack vectors for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal...
These PoCs are unverified and could contain malware. Use at your own risk.
nuclei · Created Unknown
Timeline
12:57 UTC
Exploit observed in malware
23:15 UTC
Evidence-backed exploitation signal
14:21 UTC
Public proof-of-concept code published
17:24 UTC
Indicators of compromise recorded
14:20 UTC
Exploitation attested by an external source
04:30 UTC
Scanner coverage available
14:21 UTC
Exploitation attested by an external source
14:21 UTC
Exploitation attested by an external source
14:00 UTC
Listed in the CISA Known Exploited Vulnerabilities catalog
10:28 UTC
Exploitation attested by an external source
18:02 UTC
Exploitation attested by an external source
07:34 UTC
High-confidence, third-party attested exploitation
03:47 UTC
Scanner coverage available
21:32 UTC
Vulnerability disclosed publicly
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/GHSA-JQXW-84HX-6QJ5
Free JSON includes basic KEV fields{
"ghsa_id": "GHSA-JQXW-84HX-6QJ5",
"confidence": "Confirmed",
"cvss_score": 4.7,
"cvss_estimated": false,
"epss_score": 0.93905,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": true
},
"sensor_telemetry": { "attempts": 11, "sensors": 9 }
}