2026-05-30HIGHexploitedCISA marks the exploited GlobalProtect VPN bypass as used in ransomware; Arctic Wolf traced Qilin intrusions to it
Palo Alto Networks Prisma Access
product · product:palo-alto-networks-prisma-access
Coverage
1
first 2026-05-30 → last 2026-10-06
Latest activity
2026-10-06
CISA marks the exploited GlobalProtect VPN bypass as used in ransomware; Arctic Wolf traced Qilin intrusions…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, finance, healthcare · regions: europe
Sources cited
7
6 hosts
Action items (2)
Do-now tasks recorded on the entries about Palo Alto Networks Prisma Access, newest first. Check the date before acting on an older one.
- Patch every PAN-OS GlobalProtect portal and gateway to the fixed release in Palo Alto's advisory for its train, or disable authentication override cookies or give them a certificate that no other service uses, then force one re-authentication so override cookies regenerate.2026-05-30CVE-2026-0257
- On every GlobalProtect gateway that was internet-reachable and unpatched at any time since 2026-05-17, treat the network behind it as a ransomware compromise-assessment target: review VPN sessions that authenticated by cookie from unexpected sources, then check Windows hosts for the artifacts Arctic Wolf describes (a ransomware payload staged under C:\\PerfLogs, a PsExec service, an LSASS dump written through comsvcs.dll to an .odt file, an ntdsutil media copy of the Active Directory database, and cleared event logs).2026-05-30CVE-2026-0257
Defender insights
What each entry about Palo Alto Networks Prisma Access tells a defender to do, newest first.
Exposure · detection
Story timeline
Hunting pivots
CVEs (exploited first)
Releases covered
Palo Alto Networks Prisma Access
ATT&CK techniques (15 across 10 tactics)
15 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExternal Remote Services · Exploit Public-Facing Application
- ExecutionScheduled Task/Job: Scheduled Task · System Services: Service Execution
- PersistenceScheduled Task/Job: Scheduled Task · External Remote Services · Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- Privilege EscalationScheduled Task/Job: Scheduled Task · Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- Defense ImpairmentDisable or Modify Tools · Disable or Modify Tools: Clear Windows Event Logs
- Credential AccessOS Credential Dumping: LSASS Memory · OS Credential Dumping: NTDS
- Lateral MovementRemote Services: Remote Desktop Protocol · Remote Services: SMB/Windows Admin Shares
- Command and ControlRemote Access Tools
- ExfiltrationExfiltration Over Web Service: Exfiltration to Cloud Storage
- ImpactData Encrypted for Impact · Inhibit System Recovery
Initial Access TA0001
T1133External Remote Services×1
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.
Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗
Execution TA0002
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗
T1569.002System Services: Service Execution×1
Adversaries may abuse the Windows service control manager to execute malicious commands or payloads. The Windows service control manager (<code>services.exe</code>) is an interface to manage and manipulate services. The service control manager is accessible to users via GUI components as well as system utilities such as <code>sc.exe</code> and Net.
Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗
Persistence TA0003
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗
T1133External Remote Services×1
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.
Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.
Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗
Privilege Escalation TA0004
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.
Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗
Defense Impairment TA0112
T1685Disable or Modify Tools×1
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.
Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗
T1685.005Disable or Modify Tools: Clear Windows Event Logs×1
Adversaries may clear Windows Event Logs to hide the activity of an intrusion. Windows Event Logs are a record of a computer's alerts and notifications. There are three system-defined sources of events: System, Application, and Security, with five event types: Error, Warning, Information, Success Audit, and Failure Audit.
Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗
Credential Access TA0006
T1003.001OS Credential Dumping: LSASS Memory×1
Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). After a user logs on, the system generates and stores a variety of credential materials in LSASS process memory. These credential materials can be harvested by an administrative user or SYSTEM and used to conduct Lateral Movement using Use Alternate Authentication Material.
Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗
T1003.003OS Credential Dumping: NTDS×1
Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights. By default, the NTDS file (NTDS.dit) is located in <code>%SystemRoot%\NTDS\Ntds.dit</code> of a domain controller.
Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗
Lateral Movement TA0008
T1021.001Remote Services: Remote Desktop Protocol×1
Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.
Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗
T1021.002Remote Services: SMB/Windows Admin Shares×1
Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB). The adversary may then perform actions as the logged-on user.
Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗
Command and Control TA0011
T1219Remote Access Tools×1
An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.
Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗
Exfiltration TA0010
T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage×1
Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.
Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗
Impact TA0040
T1486Data Encrypted for Impact×1
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.
Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗
T1490Inhibit System Recovery×1
Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery. This may deny access to available backups and recovery options.
Evidence: 2026-05-30/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen · ATT&CK page ↗
Entries about Palo Alto Networks Prisma Access (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- arcticwolf.com2 (29%)
- cisa.gov1 (14%)
- rapid7.com1 (14%)
- security-hub.ncsc.admin.ch1 (14%)
- security.paloaltonetworks.com1 (14%)
- unit42.paloaltonetworks.com1 (14%)
All cited sources (7)
- arcticwolf.comArctic Wolf, 2026-06-11https://arcticwolf.com/resources/blog/arctic-wolf-observes-increase-in-palo-alto-networks-globalprotect-authentication-bypass-exploitation-via-cve-2026-0257/
- arcticwolf.comArctic Wolf Labshttps://arcticwolf.com/resources/blog/exploitation-of-cve-2026-0257-leads-to-qilin-ransomware/
- cisa.govCISA Known Exploited Vulnerabilities cataloghttps://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
- rapid7.comRapid7 ETRhttps://www.rapid7.com/blog/post/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257/
- security-hub.ncsc.admin.chNCSC-CH Security Hub, 2026-06-16https://security-hub.ncsc.admin.ch/#/posts/12605
- security.paloaltonetworks.comPalo Alto Networks PSIRThttps://security.paloaltonetworks.com/CVE-2026-0257
- unit42.paloaltonetworks.comUnit 42, 2026-06-09https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/