Palo Alto PAN-OS Under Active Attack: Four Vulnerabilities Demand Immediate Action from GCC Network Teams

Palo Alto Networks is facing four active CVEs across PAN-OS. One is already being exploited in the wild and listed by CISA. GCC enterprises running GlobalProtect or PA-Series firewalls must act now.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region5 min read
Enterprise network security engineer reviewing Palo Alto PAN-OS firewall vulnerability dashboards in a corporate operations centre

Enterprise network security engineer reviewing Palo Alto PAN-OS firewall vulnerability dashboards in a corporate operations centre

Palo Alto Networks has disclosed and confirmed exploitation of four separate vulnerabilities in its PAN-OS firewall software, published across a four-week window between mid-May and mid-June 2026. Taken together, they represent one of the more consequential patch cycles the vendor has issued this year, and every enterprise in the Gulf running PA-Series, VM-Series, or GlobalProtect infrastructure needs to understand what is at stake.

The most urgent of the four is CVE-2026-0257, an authentication bypass affecting the GlobalProtect portal and gateway components of PAN-OS. The vulnerability allows a remote, unauthenticated attacker to forge authentication override cookies and establish an unauthorised VPN connection into a targeted network. The flaw was initially rated at medium severity when Palo Alto disclosed it on 13 May 2026, but that assessment was quickly revised upward to critical after Rapid7 confirmed active exploitation in the wild across multiple customer environments, assigning it a CVSS score of 9.1. The US Cybersecurity and Infrastructure Security Agency added it to the Known Exploited Vulnerabilities catalog on 29 May 2026, triggering mandatory remediation deadlines for Federal Civilian Executive Branch agencies.

What distinguishes CVE-2026-0257 from a standard patch advisory is what it enables. An unauthorised VPN tunnel, once established, behaves like any legitimate remote access session. It does not obviously trip outbound traffic alerts. It can survive reboots and persist through routine log reviews. In environments managing thousands of concurrent VPN sessions across distributed Gulf offices, identifying one additional rogue tunnel without targeted threat hunting is genuinely difficult. Unit 42 confirmed it observed two distinct waves of exploitation, the first originating from Vultr-hosted infrastructure on 18 May and a second wave on 21 May, with attackers using forged cookies targeting local administrator accounts to successfully authenticate to GlobalProtect gateways. The flaw specifically applies to deployments where authentication override cookies are enabled alongside a specific certificate configuration.

Organisations that have not yet patched should immediately restrict GlobalProtect portal and gateway access to trusted internal IP addresses, or disable the authentication override feature entirely. Generating a new, exclusive certificate for the feature also serves as a temporary mitigation. Where possible, upgrade to a fixed PAN-OS version without delay.

The three additional vulnerabilities, disclosed on 10 and 12 June 2026, carry a different risk profile. None is currently known to be exploited in the wild, but each offers meaningful post-compromise leverage and warrants treatment as high priority given the active threat environment surrounding PAN-OS.

CVE-2026-0273 is a command injection flaw rated CVSS 6.1 under CVSS 4.0 (with a base score reaching 8.6 when exploit maturity is factored out). An authenticated administrator can, via either the PAN-OS CLI or the web management interface, inject OS-level commands and execute them with root privileges, bypassing all built-in system restrictions. The flaw affects PA-Series and VM-Series firewalls and Panorama appliances running PAN-OS branches 10.2, 11.1, 11.2, and 12.1, up to specific hotfix thresholds. No special configuration is required beyond administrative login access. Organisations with Threat Prevention subscriptions can block exploit attempts by enabling Threat IDs 510028 and 510029, provided management traffic is routed through a data-plane interface.

CVE-2026-0272 is a privilege escalation flaw in the PAN-OS CLI, rated CVSS 6.0, which allows an authenticated administrator to perform actions with root-level privilege. The attack surface is slightly narrower than CVE-2026-0273 since it requires CLI access rather than web UI exposure, but the affected hardware platforms and PAN-OS version branches are identical.

CVE-2026-0269 introduces a memory corruption vulnerability in tunnel traffic processing, rated CVSS 4.6, that affects firewalls configured with IPsec tunnels or GlobalProtect gateways. An authenticated user on an adjacent network can send a maliciously crafted packet to trigger repeated firewall reboots, pushing the device into maintenance mode and causing sustained denial of service to VPN and remote access services. Palo Alto has confirmed no practical workaround for CVE-2026-0269, making patching the only reliable mitigation.

Fixed versions for the June trio are as follows. For CVE-2026-0273: 10.2.18-h7, 11.1.15, 11.2.12, 12.1.7. For CVE-2026-0272: 10.2.18-h5, 11.1.14, 11.2.11, 12.1.5. For CVE-2026-0269: 10.2.18, 11.1.12, 11.2.10, 12.1.5. Organisations running older unsupported branches should migrate to a supported and fixed release rather than rely on configuration alone.

Across all four vulnerabilities, Palo Alto's guidance converges on the same hardening posture that good firewall governance demands in any case: restrict management interface access to trusted internal IP addresses only, limit CLI access to the smallest possible group of administrators, and route all administrative traffic through a hardened jump host. These are not compensating controls to be applied while a patch is pending; they are the baseline architecture that should already be in place for any internet-adjacent perimeter device.

For GCC enterprises, the broader context matters. Palo Alto Networks holds significant market share across government, financial services, and critical infrastructure deployments in the UAE and Saudi Arabia, and the convergence of four CVEs within a single month, one already under active exploitation, reinforces the importance of structured vulnerability management programmes rather than reactive patching. As MENA Cyber Wire has covered, Palo Alto remains one of the most widely evaluated security platforms in the Gulf, which makes patch cadence for its products a board-level conversation, not just a network team task.

Enterprises should audit their PAN-OS versions immediately against the affected ranges, prioritise CVE-2026-0257 remediation where GlobalProtect is deployed, and schedule emergency patching for the June trio within the current maintenance window. Where firewall management interfaces remain reachable from semi-trusted or internet-facing segments, treat the exposure as an active risk.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.

Intelligence Focus Areas

Firewall SecurityNetwork Vulnerability ManagementCISA Known Exploited VulnerabilitiesEnterprise Patch StrategyVPN SecurityPAN-OS Security AdvisoriesGulf Enterprise CybersecurityGCC Threat Intelligence