Skip to main content
EPSS 95.2%top 0.14%

CVE-2026-0257: CWE-565 Reliance on Cookies without Validation and Integrity Checking in Palo Alto Networks Cloud NGFW

0
High
Published: 08/07/2026 (08/07/2026, 02:45:38 UTC)
Source: CVE Database V5
Vendor/Project: Palo Alto Networks
Product: Cloud NGFW

Description

Arctic Wolf Labs has been tracking multiple campaigns built around CastleLoader, a multi-stage shellcode loader that has evolved significantly. Three distinct campaigns were identified: Urutyka, Garrigin, and Noidret. The most significant development is the integration of NeedleStealer framework payloads, marking the first observed use of Rust and Golang tooling in this campaign cluster. NeedleStealer includes a Rust-based desktop cryptocurrency wallet spoofer targeting Ledger, Trezor, and Exodus wallets, and a Golang-based malicious browser extension installer. The campaigns utilize obfuscated PowerShell stagers, IronPython runtimes, and NodeJS-based shellcode injectors. Infrastructure analysis revealed consistent naming patterns, staged domains for future operations, and the use of fraudulently obtained code-signing certificates. The campaigns consistently deploy NetSupport RAT and CastleStealer alongside the new NeedleStealer payloads, suggesting an expansion toward high-value cryptocurrency targeting.

CVSS v4.0

Score 7.8high

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
Low
Vuln. Integrity
None
Vuln. Availability
None
Subsq. Confidentiality
High
Subsq. Integrity
High
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/E:A/AU:N/R:A/V:D/RE:M/U:Red

Affected software

Palo Alto Networks

Cloud NGFW

Palo Alto Networks

PAN-OS

Affected versions
>=12.1.0 <12.1.7>=11.2.0 <11.2.12>=11.1.0 <11.1.15>=10.2.0 <10.2.18-h6

Palo Alto Networks

Prisma Access

Affected versions
>=10.2.0 <10.2.10-h36>=11.2.0 <11.2.7-h13

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/08/2026, 12:41:12 UTC

Technical Analysis

This vulnerability (CVE-2026-0257) affects Palo Alto Networks Cloud NGFW and is categorized under CWE-565, indicating reliance on cookies without proper validation and integrity checking. The CVSS 4.0 vector indicates network attack vector, low attack complexity, no privileges or user interaction required, but with high scope and impact on confidentiality, integrity, and availability. The vulnerability could allow attackers to hijack sessions or manipulate authentication cookies. The description references related threat actor campaigns involving malware such as CastleLoader and NeedleStealer that target cryptocurrency wallets and use advanced techniques including obfuscated PowerShell, IronPython runtimes, and code-signing certificates. However, the vulnerability details and exploitation specifics are limited, and no patch or remediation level has been provided by the vendor.

Potential Impact

Successful exploitation could lead to session hijacking or unauthorized access due to improper cookie validation, potentially compromising confidentiality, integrity, and availability of the affected system. The CVSS score of 7.8 reflects a high impact. The association with sophisticated malware campaigns targeting cryptocurrency wallets suggests a risk of financial theft or data compromise if exploited. However, no known exploits are currently reported in the wild.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary mitigation has been published by Palo Alto Networks. Organizations should monitor vendor communications for updates and apply patches promptly once available. Until then, consider additional monitoring of session management and cookie handling as a precaution.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
palo_alto
Date Reserved
2025-11-03T20:44:17.691Z
Cvss Version
4.0
State
PUBLISHED

Indicators of Compromise

Domain

ValueDescriptionCopy
domainteamsvoicepremium.com
domainitalianhitech.com
domainebedidance.com
domaindrrajivparti.com
domainp-rala.com
domainavivtech.org
domainclaudettes.net
domainskipraid.com
domainclaudenell.net
domaineazysitebuilder.com
domainfangorinaf.com
domaingarrigin.com
domaingoodbytetelegramm.com
domaingrenagana.com
domaingrorriner.com
domainhobtech.net
domainkaneta.cc
domainmonblare.com
domainnoidret.com
domainquiantar.com
domainqxvnrta.com
domainsocom-game.com
domainstrainted.com
domainthenugcompany.org
domainurutyka.com
domainidp.kualabemo.com
domainidp.keyreniao.com
domainidp.korminel.com
domainmsauth.monlinelogicaline.com
domainmslogin.milocaroline.com
domainmsonline.logicalineonline.com
domainoffice.ofrecie.com

Ip

ValueDescriptionCopy
ip94.26.90.112
ip179.132.128.189
ip216.107.139.188
ip91.92.33.167

Cve

ValueDescriptionCopy
cveCVE-2026-0257
cveCVE-2026-48558
cveCVE-2026-6875
cveCVE-2026-18577
cveCVE-2026-18556

Hash

ValueDescriptionCopy
hashd26ea6828cc01ae151d99bbee78c4e6d132e9077842a558bce3901fa0970d9be
hash2fcf553b9656523b3207c08cdf16f7be9a25e55cf8c29f5caf933151c9214367
hash1390903f57b21f346193aefbbfd36759
hash4d5f81bf79554aa7a2187e6ffbc9702a
hash6728b11f74fd435f926ed25c5f2952bb
hash0c48fd6a18ad9c701b254bbdd412efbf7dfdd2be6534a61c14bce719d259df9f
hashedff43ecdf7aa476331d925db04e68a2251920165a2109be9df91a56d86b87c7
hashfa67487da701ce1d61ee3abb84869f669a6c2aa50ca0148a3c4a87e667716638

Url

ValueDescriptionCopy
urlhttp://94.26.90.112/dl-callback/6dkcdpd7-4jacbuf9-prutgux4-2ybssc8v/traffic1.exe/1390903f57b21f346193aefbbfd36759
urlhttp://eazysitebuilder.com:4889
urlhttp://goodbytetelegramm.com/xxx/main
urlhttp://socom-game.com:5500
urlhttp://urutyka.com/xxx/viewer32

Threat ID: 6a04c4b4cbff5d8610fad297

Added to database: 05/13/2026, 18:36:36 UTC

Last enriched: 08/08/2026, 12:41:12 UTC

Last updated: 09/14/2026, 22:01:31 UTC

Views: 286

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses