A GlobalProtect login bypass is enough to hand an attacker a working VPN session, which turns the gateway into internal network access instead of a blocked edge. The practical failure is not the portal itself. It is that a trusted remote-access login can become a live foothold without a valid credential, so the attacker starts inside the perimeter.
Arctic Wolf says Qilin is using CVE-2026-0257 against Palo Alto PAN-OS portal and gateway components. The group has tied that access to SSL VPN sessions, credential harvesting, lateral movement through administrative shares, log clearing, and ransomware deployment, with activity ranging from encryption-only runs to double extortion.
That makes this a recurring remote-access compromise pattern, not a one-off firewall bug. If a gateway can grant trusted internal access after authentication is bypassed, patching closes the flaw but does not change the fact that exposed deployments were usable as an intrusion path until they were fixed.