The vulnerability is remotely reachable over the network through a GlobalProtect gateway or portal, requires no authentication or user interaction, and is assessed in the normalized record as low complexity. It has been exploited in the wild, and third-party proof of concept code has been publicly disclosed. Unit 42 tracks the initial activity as Operation MidnightEclipse, while Volexity attributes the observed activity to the actor it calls UTA0218. Investigations recorded exploitability testing through zero-byte file creation, as well as compromises involving reverse shells, tool downloads, firewall configuration collection, and lateral movement into victim networks. Palo Alto Networks and Unit 42 stated at the time of their updates that they were not aware of malicious use of post-exploitation persistence techniques that survive resets and upgrades, although third-party proof of concept code for those techniques existed.