Skip to content
feed: live
>_ 0dayNews
palo alto networks
● Breaking

Qilin exploits PAN-OS GlobalProtect CVE-2026-0257

Arctic Wolf documents Qilin ransomware breaching networks through a two-month-old PAN-OS GlobalProtect authentication bypass, and assesses with moderate confidence that intrusions are ongoing.

Qilin exploits PAN-OS GlobalProtect CVE-2026-0257
Photo: panumas nikhomkhai / Pexels · Pexels License
airgap airgap · Published · 3 min read

Confirmed reporting by Arctic Wolf Labs via BleepingComputer, 2026-07-21. The Qilin ransomware operation is using CVE-2026-0257, the PAN-OS GlobalProtect authentication-bypass flaw Palo Alto Networks patched on May 13, to reach victim networks. Arctic Wolf observed multiple intrusions in June that traced back to unpatched GlobalProtect portals. Confidence: moderate, per Arctic Wolf’s own assessment, that exploitation is ongoing based on continued scanning activity.

Timeline

  • May 13, 2026. Palo Alto Networks publishes the PAN-OS advisory for CVE-2026-0257 and ships fixed builds: 12.1.7, 11.2.12, 11.1.15, 10.2.18-h6. Cloud NGFW and Panorama are not affected.
  • May 17, 2026. Rapid7 reports the first observed exploitation attempts, four days after the patch. No attribution yet.
  • May 29, 2026. CISA adds CVE-2026-0257 to the KEV catalog and orders federal civilian agencies to patch within three days — the shorter-than-default deadline the KEV process reserves for perimeter devices under active exploitation.
  • June 2026. Arctic Wolf, per its writeup summarized by BleepingComputer, observes multiple Qilin ransomware intrusions where the initial access vector maps to CVE-2026-0257.
  • July 21, 2026. Coverage today.

That’s two months between patch and this attribution. It is not new exploitation of an unknown flaw. It is old exploitation of a flaw that a lot of people did not patch.

What the flaw is

Palo Alto’s own advisory calls it a GlobalProtect authentication bypass in the portal and gateway. The vendor’s CVSS 4.0 score is 7.8 (High); NVD scores it 9.1 under CVSS 3.1 (Critical). The site follows source scoring — the primary source disagreement is worth flagging, not resolving.

The exploitation precondition, per the advisory, is a specific configuration where authentication override cookies are enabled alongside a particular certificate setup. Neither the advisory nor the public exploitation writeups reproduce the trigger. This piece won’t either. Readers who need the technical mechanics should read the vendor advisory directly.

What the flaw gives an attacker: an authenticated VPN connection into a network that presumed the GlobalProtect portal was doing its job. From there, Qilin’s playbook is the one it has been running since 2022 — enumerate, escalate, exfiltrate, encrypt. Arctic Wolf did not publish per-victim numbers in the material covered by BleepingComputer.

Scale exposure

Shadowserver tracks over 167,000 GlobalProtect instances exposed to the internet. Patch status on the majority is not knowable from the outside. If even a small fraction never took the May 13 fix — and the fact that exploitation was still worth Qilin’s time in June suggests that fraction is not small — the addressable target set is measured in tens of thousands of edge appliances.

Qilin, per BleepingComputer’s summary of the operation’s history, has claimed over 2,000 victims across its run. The group does not need CVE-2026-0257 to keep going; it just needs a fresh vector into unpatched perimeter kit, and this is one.

What actually changes today

The patch shipped two months ago. If the appliance took it, this article is not about you. If it did not:

  • Get to a fixed build. 12.1.7, 11.2.12, 11.1.15, or 10.2.18-h6 minimum, per the vendor. Prisma Access users should read the advisory directly for the cloud-side patch levels.
  • Presume compromise on any appliance that stayed vulnerable past May 29. CISA’s three-day deadline for federal agencies is a proxy for how urgent the KEV team scored this. A perimeter box that was reachable and unpatched for a month while exploitation was public and attribution was not yet published is not a box you can wave through on a hunt. Pull GlobalProtect authentication logs, correlate against unexpected session establishment, and hunt for the post-access behaviors Qilin is documented for: SMB enumeration, credential theft from LSASS, and staged data movement.
  • Rotate any credentials that transited a vulnerable GlobalProtect session. If the auth-bypass gave someone an unauthorized VPN tunnel, everything reachable from that tunnel is in scope for follow-on credential compromise.
  • Do not wait for a specific victim disclosure. Arctic Wolf’s public writeup will not enumerate every environment it observed. The confidence-labeling above (“moderate,” “ongoing,” “observed”) is Arctic Wolf’s; treat it as an operational signal, not a courtroom standard.

What is still unconfirmed

  • Victim identities. Not disclosed in the BleepingComputer summary.
  • Whether Qilin is the only crew using the flaw. Rapid7’s May 17 detection preceded the June Qilin cluster and was not attributed. There may be more than one operator on this vector.
  • The exploit chain that closes the pre-auth to post-auth gap. Vendor advisory and public reporting both stop short of walking the trigger, and this piece does the same.

Sourcing

Related CVEs

Found this useful? Share it.