Vulnerabilities & Exploits · Web App Attack

Edge Appliances Become Ransomware’s Preferred Front Door

Perimeter boxes are no longer just exposed services to patch. Qilin is already using the GlobalProtect authentication bypass as a foothold, and the same edge-access pattern is spreading across VPN and firewall products from multiple vendors.

Arctic Wolf says CVE-2026-0257 in Palo Alto GlobalProtect portal and gateway was exploited within days of disclosure, with intrusions in June tied to Qilin. The same cluster also points to Fortinet FortiGate, Citrix NetScaler, and Check Point Remote Access VPN, which shows the attack surface is the trust boundary itself, not one brand or one CVE.

That changes the defensive problem. Once the edge device falls, it becomes a trusted path into the internal network for ransomware staging and follow-on access, so patching one appliance class no longer covers the risk.

4 sources · Jul 24

CVE-2026-0257

NVD KEV

Known exploited · CISA KEV

EPSS 95% (100th percentile).

CISA federal remediation date Jun 1 · date passed

Timeline

Sources

Vendor digest: Fortinet

Vendor digest: Citrix

Vendor digest: Palo Alto Networks

Part of the PlainSec briefing for 2026-07-24

Every edition of this story: Edge Appliances Become Ransomware’s Preferred Front Door

More from today