Skip to content
Tech News
← Back to articles

Critical Palo Alto VPN bug now exploited by Qilin ransomware gang

read original more articles
Why This Matters

The exploitation of a critical Palo Alto Networks VPN vulnerability (CVE-2026-0257) by the Qilin ransomware gang highlights the ongoing threat of cyberattacks targeting enterprise infrastructure. This incident underscores the importance of timely patching and robust security measures to prevent ransomware breaches that can disrupt operations and compromise sensitive data.

Key Takeaways

The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf.

Palo Alto Networks addressed the vulnerability (CVE-2026-0257) on May 13 and warned that attackers had begun abusing it to breach corporate networks after Rapid7 reported observing it being exploited against numerous customers starting on May 17.

"GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection," the company warned at the time. "Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied."

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) also added the flaw to its Known Exploited Vulnerability catalog on May 29, ordering federal agencies to secure their GlobalProtect VPN instances within three days.

On Monday, Arctic Wolf Labs revealed that it observed multiple cases where threat actors exploited CVE-2026-0257 in attacks that led to domain-wide Qilin ransomware encryption, noting that evidence collected while investigating these incidents points to multiple Qilin affiliates actively exploiting this flaw to breach targets' networks.

"Arctic Wolf investigated multiple distinct intrusions during June 2026 that resulted in Qilin ransomware deployment, all originating from exploitation of CVE-2026-0257 against Palo Alto Networks firewall appliances," it said.

"Post-exploitation tradecraft varied across intrusions, from rapid encryption-only operations to full double-extortion, possibly suggesting multiple affiliates operating under the Qilin ransomware-as-a-service (RaaS) umbrella."

Qilin CVE-2026-0257 attack chain (Arctic Wolf)

"Arctic Wolf Labs assesses with moderate confidence that intrusions leveraging CVE-2026-0257 and leading to Qilin ransomware deployment are likely ongoing. This assessment is based on the extensive scanning activity observed and the RaaS model's tendency to distribute successful exploits among multiple affiliates," the company added.

Internet threat watchdog Shadowserver now tracks over 167,000 GlobalProtect VPN instances exposed online, while Shodan found over 172,000 IPs with a GlobalProtect fingerprint. However, there is no information on how many of them are honeypots or have already been patched against CVE-2026-0257 attacks.

... continue reading