Back to Feed
RansomwareJul 21, 2026

Critical Palo Alto VPN bug now exploited by Qilin ransomware gang

Qilin ransomware gang exploits critical Palo Alto VPN bug for network breaches.

Summary

The Qilin ransomware gang is actively exploiting a critical authentication bypass vulnerability (CVE-2026-0257) in Palo Alto Networks' PAN-OS GlobalProtect software. This flaw allows attackers to bypass security restrictions and establish unauthorized VPN connections, leading to network intrusions and subsequent Qilin ransomware deployment. Multiple affiliates are believed to be operating under the Qilin RaaS umbrella, indicating ongoing exploitation.

Full text

Critical Palo Alto VPN bug now exploited by Qilin ransomware gang By Sergiu Gatlan July 21, 2026 06:12 AM 0 The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf. Palo Alto Networks addressed the vulnerability (CVE-2026-0257) on May 13 and warned that attackers had begun abusing it to breach corporate networks after Rapid7 reported observing it being exploited against numerous customers starting on May 17. "GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection," the company warned at the time. "Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied." The U.S. Cybersecurity and Infrastructure Security Agency (CISA) also added the flaw to its Known Exploited Vulnerability catalog on May 29, ordering federal agencies to secure their GlobalProtect VPN instances within three days. On Monday, Arctic Wolf Labs revealed that it observed multiple cases where threat actors exploited CVE-2026-0257 in attacks that led to domain-wide Qilin ransomware encryption, noting that evidence collected while investigating these incidents points to multiple Qilin affiliates actively exploiting this flaw to breach targets' networks. "Arctic Wolf investigated multiple distinct intrusions during June 2026 that resulted in Qilin ransomware deployment, all originating from exploitation of CVE-2026-0257 against Palo Alto Networks firewall appliances," it said. "Post-exploitation tradecraft varied across intrusions, from rapid encryption-only operations to full double-extortion, possibly suggesting multiple affiliates operating under the Qilin ransomware-as-a-service (RaaS) umbrella." Qilin CVE-2026-0257 attack chain (Arctic Wolf) "Arctic Wolf Labs assesses with moderate confidence that intrusions leveraging CVE-2026-0257 and leading to Qilin ransomware deployment are likely ongoing. This assessment is based on the extensive scanning activity observed and the RaaS model's tendency to distribute successful exploits among multiple affiliates," the company added. Internet threat watchdog Shadowserver now tracks over 167,000 GlobalProtect VPN instances exposed online, while Shodan found over 172,000 IPs with a GlobalProtect fingerprint. However, there is no information on how many of them are honeypots or have already been patched against CVE-2026-0257 attacks. Qilin is a Ransomware-as-a-Service (RaaS) operation that surfaced in August 2022 under the "Agenda" name and has since claimed responsibility for more than 2,000 victims on its dark web leak site. The list of victims includes many high-profile organizations such as automotive giants Nissan and Yangfeng, Japanese beer giant Asahi, pathology services provider Synnovis, publishing giant Lee Enterprises, and Australia's Court Services Victoria. Palo Alto Networks' products and services are used by over 70,000 customers worldwide, including most of the largest U.S. banks and 90% of Fortune 10 companies. Test every layer before attackers do Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. Get the whitepaper Related Articles: Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacksCISA gives feds 3 days to patch Check Point VPN bug exploited as zero-dayCheck Point links VPN zero-day attacks to Qilin ransomware gangUS sanctions VPN, malware providers for enabling ransomware attacksCISA: Windows BlueHammer flaw now exploited by ransomware gangs

Indicators of Compromise

  • cve — CVE-2026-0257

Entities

Qilin (threat_actor)Palo Alto Networks (vendor)PAN-OS GlobalProtect (product)