


Perceptive Security
SOC/SIEM Consultancy

Palo Alto Networks heeft een kwetsbaarheid verholpen in de GlobalProtect portal- en gateway-componenten van PAN-OS. Een ongeauthenticeerde kwaadwillende kan de …
Published:
30 May 2026 at 10:52:02
Alert date:
30 May 2026 at 11:00:32
Source:
ncsc.nl
Network Infrastructure, Zero-Day Vulnerabilities, Identity & Access
Palo Alto Networks has fixed a vulnerability in the GlobalProtect portal and gateway components of PAN-OS. An unauthenticated attacker can exploit the vulnerability to establish a VPN connection, gaining access to internal systems. Systems are only vulnerable when HTTPS certificates are reused and specific authentication override options are enabled. Rapid7 reports the vulnerability is being actively exploited, and proof-of-concept code is publicly available. The NCSC expects the scale of exploitation to increase in the coming period.
Technical details
Mitigation steps:
Affected products:
Palo Alto Networks PAN-OS
Prisma Access
GlobalProtect
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
