Critical Palo Alto VPN bug now exploited by Qilin ransomware gang

Qilin ransomware

The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims’ networks, according to cybersecurity company Arctic Wolf.

Palo Alto Networks addressed the vulnerability (CVE-2026-0257) on May 13 and warned that attackers had begun abusing it to breach corporate networks after Rapid7 reported observing it being exploited against numerous customers starting on May 17.

“GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection,” the company warned at the time. “Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied.”

image

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) also added the flaw to its Known Exploited Vulnerability catalog on May 29, ordering federal agencies to secure their GlobalProtect VPN instances within three days.

On Monday, Arctic Wolf Labs revealed that it observed multiple cases where threat actors exploited CVE-2026-0257 in attacks that led to domain-wide Qilin ransomware encryption, noting that evidence collected while investigating these incidents points to multiple Qilin affiliates actively exploiting this flaw to breach targets’ networks.

“Arctic Wolf investigated multiple distinct intrusions during June 2026 that resulted in Qilin ransomware deployment, all originating from exploitation of CVE-2026-0257 against Palo Alto Networks firewall appliances,” it said.

“Post-exploitation tradecraft varied across intrusions, from rapid encryption-only operations to full double-extortion, possibly suggesting multiple affiliates operating under the Qilin ransomware-as-a-service (RaaS) umbrella.”

Qilin CVE-2026-0257 attack chain
Qilin CVE-2026-0257 attack chain (Arctic Wolf)

“Arctic Wolf Labs assesses with moderate confidence that intrusions leveraging CVE-2026-0257 and leading to Qilin ransomware deployment are likely ongoing. This assessment is based on the extensive scanning activity observed and the RaaS model’s tendency to distribute successful exploits among multiple affiliates,” the company added.

Internet threat watchdog Shadowserver now tracks over 167,000 GlobalProtect VPN instances exposed online, while Shodan found over 172,000 IPs with a GlobalProtect fingerprint. However, there is no information on how many of them are honeypots or have already been patched against CVE-2026-0257 attacks.

Qilin is a Ransomware-as-a-Service (RaaS) operation that surfaced in August 2022 under the “Agenda” name and has since claimed responsibility for more than 2,000 victims on its dark web leak site.

The list of victims includes many high-profile organizations such as automotive giants Nissan and Yangfeng, Japanese beer giant Asahi, pathology services provider Synnovis, publishing giant Lee Enterprises, and Australia’s Court Services Victoria.

Palo Alto Networks’ products and services are used by over 70,000 customers worldwide, including most of the largest U.S. banks and 90% of Fortune 10 companies.

article image

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper