>> All posts

Exposed Palo Alto GlobalProtect VPN logins and password spraying

The short version: An internet-facing Palo Alto GlobalProtect VPN portal is, by design, a gateway into your internal network — and attackers spray common and breached passwords against these portals constantly, because one working credential lands them inside.

What you need to know

There's no CVE here — this is about the exposed VPN login and the credentials behind it. GlobalProtect is Palo Alto Networks' remote-access VPN; its whole purpose is to let authenticated users reach internal resources. That makes its login portal a uniquely valuable target: a successful login isn't access to one app, it's a standing position inside the network.

  • How they find it — crawling surfaces the recognizable GlobalProtect portal (/global-protect/login.esp) on an internet-facing host.
  • How they use it — automated, low-and-slow spraying with common and previously-breached passwords, staying under lockout thresholds.
  • What it leads to — a valid credential grants VPN access into the internal network, sensitive data, and room to expand from a trusted position.

How serious we see it

High. A VPN portal is not an ordinary web form — it's the front door to the internal network, and these appliances are among the most heavily targeted on the internet. Where MFA is enforced and passwords are strong and unique, the exposure is contained. But a weak or reused credential without MFA is a direct path inward, which is why we rate it above a typical exposed login. The steady note: it's fixable today, and confirming whether it applies to you is quick.

What to do

  • Enforce MFA on every GlobalProtect account — the single highest-value control; it defeats spraying even when a password is known.
  • Kill weak and reused passwords — enforce strong, unique credentials and check them against known-breached lists.
  • Limit and monitor failed authentication — rate-limit attempts and alert on spray patterns (many accounts, few passwords, low-and-slow).
  • Keep the appliance current — VPN gateways are frequent exploitation targets, so pair strong auth with prompt patching.
  • Confirm your exposure first — verify whether any GlobalProtect portal is reachable from the internet today.

How BreachRisk sees it

BreachRisk discovers exposed GlobalProtect portals the way an attacker would — by crawling your external footprint — and then, where authorized, goes a step further than a scanner: it safely attempts a bounded, rate-limited authentication check using exposed (breach-corpus) and common credentials, within strict non-disruptive limits rather than a brute-force flood. That's the honest difference between detecting the VPN login and demonstrating whether it actually holds.

References

See your cyber risk, proven.