CVE-2026-0257
Known exploited · CISA KEV
EPSS 95% (100th percentile).
CISA federal remediation date Jun 1 · date passed
Vulnerabilities & Exploits · Ransomware
A GlobalProtect login bypass is enough to hand an attacker a working VPN session, which turns the gateway into internal network access instead of a blocked edge. The practical failure is not the portal itself. It is that a trusted remote-access login can become a live foothold without a valid credential, so the attacker starts inside the perimeter.
Arctic Wolf says Qilin is using CVE-2026-0257 against Palo Alto PAN-OS portal and gateway components. The group has tied that access to SSL VPN sessions, credential harvesting, lateral movement through administrative shares, log clearing, and ransomware deployment, with activity ranging from encryption-only runs to double extortion.
That makes this a recurring remote-access compromise pattern, not a one-off firewall bug. If a gateway can grant trusted internal access after authentication is bypassed, patching closes the flaw but does not change the fact that exposed deployments were usable as an intrusion path until they were fixed.
2 sources · Jul 21
Known exploited · CISA KEV
EPSS 95% (100th percentile).
CISA federal remediation date Jun 1 · date passed
The Hacker News
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
Attackers exploit PAN-OS CVE-2026-0257 to deploy Qilin ransomware, with intrusions ranging from rapid encryption to data theft and double extortion.
originalBleepingComputer
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf.
originalVendor digest: Palo Alto Networks
Part of the PlainSec briefing for 2026-07-21
Every edition of this story: GlobalProtect Auth Bypass Now Opens the Inside