Vulnerabilities · 55 days ago

GlobalProtect Auth Bypass Now Opens the Inside

A GlobalProtect login bypass is enough to hand an attacker a working VPN session, which turns the gateway into internal network access instead of a blocked edge. The practical failure is not the portal itself. It is that a trusted remote-access login can become a live foothold without a valid credential, so the attacker starts inside the perimeter.

Arctic Wolf says Qilin is using CVE-2026-0257 against Palo Alto PAN-OS portal and gateway components. The group has tied that access to SSL VPN sessions, credential harvesting, lateral movement through administrative shares, log clearing, and ransomware deployment, with activity ranging from encryption-only runs to double extortion.

That makes this a recurring remote-access compromise pattern, not a one-off firewall bug. If a gateway can grant trusted internal access after authentication is bypassed, patching closes the flaw but does not change the fact that exposed deployments were usable as an intrusion path until they were fixed.

CVE-2026-0257

NVD KEV

Known exploited · CISA KEV

EPSS 95% (100th percentile).

CISA federal remediation date Jun 1 · date passed

Timeline

Sources

2 sources covering this story

Entities

Vendor digest: Palo Alto Networks

Part of the PlainSec briefing for 2026-07-22

Editions

Related stories