All stories

Qilin ransomware group exploits critical Palo Alto VPN authentication bypass for network access

The Qilin ransomware gang is actively exploiting a critical authentication bypass in Palo Alto Networks PAN-OS GlobalProtect. This flaw allows attackers to establish unauthorized VPN connections, leading to domain-wide encryption and double-extortion attacks. Patch your GlobalProtect instances immediately.

Summary

Threat actors are using a critical vulnerability in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS software to breach corporate networks. The flaw, identified as CVE-2026-0257, enables an attacker to bypass security restrictions and establish unauthorized VPN connections.

While Palo Alto Networks addressed the issue on May 13, active exploitation was observed by Rapid7 starting May 17. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on May 29, issuing a directive for federal agencies to secure their instances within three days.

What happened

Arctic Wolf Labs has documented multiple intrusions throughout June 2026 where attackers exploited CVE-2026-0257 to deploy Qilin ransomware. These attacks resulted in domain-wide encryption. The observed post-exploitation activity varied, ranging from rapid encryption-only operations to full double-extortion tactics. This variation suggests that multiple affiliates operating under the Qilin Ransomware-as-a-Service (RaaS) model are currently targeting vulnerable systems.

The scale of potential exposure is significant. Internet threat watchdog Shadowserver tracks over 167,000 GlobalProtect VPN instances exposed online, while Shodan has identified more than 172,000 IPs with a GlobalProtect fingerprint. It remains unconfirmed how many of these instances are currently patched or protected by mitigations.

Technical details

The vulnerability is an authentication bypass located within the GlobalProtect portal and gateway components of PAN-OS. By exploiting this flaw, an attacker can circumvent established security restrictions to gain unauthorized access via a VPN connection. s

The technical impact is characterized as total for the affected components. While the issue impacts the GlobalProtect functionality, Panorama and Cloud NGFW are not affected by these specific vulnerabilities.

Affected products and fixed versions

The vulnerability affects various versions of Palo Alto Networks PAN-OS. Users should verify their current version against the following list to determine if they require an update.

Product Affected Versions (Examples)
PAN-OS 10.2.0 up to (excluding) 10.2.10
PAN-OS 11.2.0 up to (excluding) 11.2.7
PAN-OS 12.1.x (various sub-versions)

Note: Specific vulnerable versions include various builds of 10.2, 11.1, 11.2, and 12.1 as detailed in vendor advisories.

Why this matters for defenders

The Qilin ransomware group has a history of high-profile targets, including Nissan, Asahi, and Synnovis, claiming over 2,000 victims since its emergence in August 2022. Because the exploit allows for unauthorized VPN access, it provides attackers with a direct entry point into internal corporate networks.

The RaaS model used by Qilin means that once an exploit like CVE-2026-0257 is successful, multiple affiliates can deploy it independently. This increases the likelihood of widespread, concurrent attacks against different organizations using the same vulnerable hardware.

Defender guidance

Immediate action is required to secure GlobalProtect instances.

  1. Apply Patches: Update PAN-OS to a fixed version immediately. Palo Alto Networks released fixes on May 13.
  2. Verify Exposure: Use tools like Shodan or internal asset inventories to identify all exposed GlobalProtect portal and gateway interfaces.
  3. Monitor for Unauthorized Access: Audit VPN logs for unusual connection patterns or successful logins that do not correspond to known user activity, especially following the exploitation window of May 17.
  4. Apply Mitigations: If an immediate patch is not possible, consult Palo Alto Networks' official advisory for available mitigations to reduce the attack surface.

Sources

  1. https://www.bleepingcomputer.com/news/security/critical-globalprotect-vpn-bug-now-exploited-in-ransomware-attacks/
  2. https://arcticwolf.com/resources/blog/exploitation-of-cve-2026-0257-leads-to-qilin-ransomware/
  3. https://nvd.nist.gov/vuln/detail/CVE-2026-0257
  4. https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search=CVE-2026-0257&field_date_added_wrapper=all&field_cve=&sort_by=field_date_added&items_per_page=20&url=
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -