Cybersecurity experts at Arctic Wolf are warning that the Qilin ransomware group is actively exploiting a critical security vulnerability in PAN-OS GlobalProtect. This flaw allows attackers to bypass authentication mechanisms and infiltrate corporate networks.
Palo Alto Networks has patched this vulnerability, identified as CVE-2026-0257, as of May 13th. However, Rapid7 reported that cybercriminals began exploiting this flaw shortly thereafter, leading to successful attacks against multiple organizations starting May 17th.
The company warns, “The GlobalProtect portal and gateway in Palo Alto Networks’ PAN-OS® software allow attackers to bypass essential security measures and establish unauthorized VPN connections.” They have noted limited exploitation attempts on unpatched PAN-OS devices lacking necessary mitigations.
On May 29th, the US Cybersecurity and Infrastructure Security Agency (CISA) included this flaw in its catalog of known exploited vulnerabilities, underscoring its significance and urging federal agencies to secure their GlobalProtect VPN instances.
Arctic Wolf Labs has reported multiple attacks where CVE-2026-0257 was exploited, leading to widespread Qilin ransomware encryption. Their investigation indicates that various Qilin affiliates are actively targeting vulnerable networks.
“In June 2026, Arctic Wolf identified several different intrusions linked to Qilin ransomware deployment, all stemming from the exploitation of CVE-2026-0257 on Palo Alto Networks firewall appliances,” the firm stated.
The post-exploitation approaches varied significantly, from quick encryption actions to extensive double extortion tactics during intrusions, suggesting a network of affiliates operating under the Qilin Ransomware-as-a-Service (RaaS) model.

Arctic Wolf Labs assesses with moderate confidence that ongoing intrusions exploiting CVE-2026-0257, leading to Qilin ransomware deployment, are likely in progress. This assessment is supported by large-scale scanning activity and the RaaS model’s tendency to distribute successful exploits among affiliates.
According to Shadowserver, there are currently over 167,000 GlobalProtect VPN instances online, with Shodan reporting over 172,000 IPs linked to GlobalProtect. However, it’s unclear how many of these instances remain unpatched against CVE-2026-0257.
Qilin, a Ransomware-as-a-Service (RaaS) operation that emerged in August 2022 under the name “Agenda,” has reportedly claimed responsibility for encrypting data from over 2,000 victims on dark web leak sites.
Notable victims of Qilin include major companies such as Nissan, Asahi, and Lee Enterprises, as well as Australia’s Court Services Victoria.
Palo Alto Networks’ products and services serve over 70,000 customers globally, including many of the largest financial institutions and 90% of Fortune 10 companies.
Security teams document only 54% of successful attacks and raise alarms on just 14%. The remainder go unnoticed.
Picus’ whitepaper outlines strategies to test SIEM and EDR rules through breach and attack simulations to detect hidden threats.
Source: www.bleepingcomputer.com




