Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 93.9%top 0.17%

CVE-2026-0257: CWE-565 Reliance on Cookies without Validation and Integrity Checking in Palo Alto Networks Cloud NGFW

0
High
Published: 07/28/2026 (07/28/2026, 03:35:18 UTC)
Source: CVE Database V5
Vendor/Project: Palo Alto Networks
Product: Cloud NGFW

Description

Arctic Wolf Labs has been tracking multiple campaigns built around CastleLoader, a multi-stage shellcode loader that has evolved significantly. Three distinct campaigns were identified: Urutyka, Garrigin, and Noidret. The most significant development is the integration of NeedleStealer framework payloads, marking the first observed use of Rust and Golang tooling in this campaign cluster. NeedleStealer includes a Rust-based desktop cryptocurrency wallet spoofer targeting Ledger, Trezor, and Exodus wallets, and a Golang-based malicious browser extension installer. The campaigns utilize obfuscated PowerShell stagers, IronPython runtimes, and NodeJS-based shellcode injectors. Infrastructure analysis revealed consistent naming patterns, staged domains for future operations, and the use of fraudulently obtained code-signing certificates. The campaigns consistently deploy NetSupport RAT and CastleStealer alongside the new NeedleStealer payloads, suggesting an expansion toward high-value cryptocurrency targeting.

CVSS v4.0

Score 7.8high

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
Low
Vuln. Integrity
None
Vuln. Availability
None
Subsq. Confidentiality
High
Subsq. Integrity
High
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/E:A/AU:N/R:A/V:D/RE:M/U:Red

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/29/2026, 20:52:18 UTC

Technical Analysis

This vulnerability (CVE-2026-0257) involves authentication bypass in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS software due to reliance on cookies without validation and integrity checking (CWE-565). Exploiting this flaw enables attackers to circumvent security controls and gain unauthorized VPN access. The issue does not impact Panorama or Cloud NGFW products. No patch or official remediation level has been provided in the available data. The CVSS 4.0 vector indicates network attack vector, low attack complexity, no privileges or user interaction required, with high scope and impact on confidentiality, integrity, and availability.

Potential Impact

Successful exploitation allows an attacker to bypass authentication mechanisms on the GlobalProtect portal and gateway, resulting in unauthorized VPN access. This could lead to unauthorized network access and potential compromise of internal resources. Panorama and Cloud NGFW are confirmed not impacted by this vulnerability.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or remediation level is provided, organizations should monitor Palo Alto Networks advisories for updates. Until a fix is available, consider restricting access to the GlobalProtect portal and gateway to trusted networks or users where feasible.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
palo_alto
Date Reserved
2025-11-03T20:44:17.691Z
Cvss Version
4.0
State
PUBLISHED
Remediation Level
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainteamsvoicepremium.com
domainitalianhitech.com
domainebedidance.com
domaindrrajivparti.com
domainp-rala.com
domainavivtech.org
domainclaudettes.net
domainskipraid.com
domainclaudenell.net
domaineazysitebuilder.com
domainfangorinaf.com
domaingarrigin.com
domaingoodbytetelegramm.com
domaingrenagana.com
domaingrorriner.com
domainhobtech.net
domainkaneta.cc
domainmonblare.com
domainnoidret.com
domainquiantar.com
domainqxvnrta.com
domainsocom-game.com
domainstrainted.com
domainthenugcompany.org
domainurutyka.com

Ip

ValueDescriptionCopy
ip94.26.90.112
ip179.132.128.189
ip216.107.139.188
ip91.92.33.167

Cve

ValueDescriptionCopy
cveCVE-2026-0257
cveCVE-2026-48558

Hash

ValueDescriptionCopy
hashd26ea6828cc01ae151d99bbee78c4e6d132e9077842a558bce3901fa0970d9be
hash2fcf553b9656523b3207c08cdf16f7be9a25e55cf8c29f5caf933151c9214367
hash1390903f57b21f346193aefbbfd36759
hash4d5f81bf79554aa7a2187e6ffbc9702a
hash6728b11f74fd435f926ed25c5f2952bb
hash0c48fd6a18ad9c701b254bbdd412efbf7dfdd2be6534a61c14bce719d259df9f
hashedff43ecdf7aa476331d925db04e68a2251920165a2109be9df91a56d86b87c7
hashfa67487da701ce1d61ee3abb84869f669a6c2aa50ca0148a3c4a87e667716638

Url

ValueDescriptionCopy
urlhttp://94.26.90.112/dl-callback/6dkcdpd7-4jacbuf9-prutgux4-2ybssc8v/traffic1.exe/1390903f57b21f346193aefbbfd36759
urlhttp://eazysitebuilder.com:4889
urlhttp://goodbytetelegramm.com/xxx/main
urlhttp://socom-game.com:5500
urlhttp://urutyka.com/xxx/viewer32

Threat ID: 6a04c4b4cbff5d8610fad297

Added to database: 05/13/2026, 18:36:36 UTC

Last enriched: 07/29/2026, 20:52:18 UTC

Last updated: 07/31/2026, 19:22:58 UTC

Views: 233

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses