Qilin Ransomware Gang Exploits Critical Palo Alto VPN Vulnerability

Qilin Ransomware Gang Exploits Critical Palo Alto VPN Vulnerability

First seen 21 Jul 2026, 10:35 UTC CybersecuritynewsBleepingcomputernvd.nist.govwww.cisa.govwww.tines.com+1 92% similarity 69.9

Article Content

Browse articles
ThreatCluster

The Qilin ransomware gang is actively exploiting a critical authentication bypass vulnerability (CVE-2026-0257) in Palo Alto Networks' GlobalProtect VPN. Discovered by Arctic Wolf Labs, the flaw allows attackers to bypass security measures and establish unauthorized VPN connections. The vulnerability was published on May 13, 2026, and was added to the CISA's Known Exploited Vulnerability catalog on May 29, 2026. Since then, multiple intrusions have been reported, leading to domain-wide ransomware encryption. Arctic Wolf noted that these attacks have been ongoing, with evidence of multiple affiliates within the Qilin Ransomware-as-a-Service (RaaS) model. Over 167,000 GlobalProtect VPN instances are exposed online, increasing the risk of exploitation. High-profile victims include organizations across various sectors, highlighting the widespread impact of this vulnerability.

Key Points: • Qilin ransomware gang exploits CVE-2026-0257 in Palo Alto VPNs. • Over 167,000 GlobalProtect VPN instances are exposed online. • Multiple high-profile organizations have been targeted in these attacks.

ThreatCluster AI

Timeline

2026-05-13
CVE-2026-0257 published
Palo Alto Networks disclosed a critical authentication bypass flaw in PAN-OS.
BleepingComputer
2026-05-29
CVE-2026-0257 added to CISA KEV
CISA added the vulnerability to its Known Exploited Vulnerability catalog, urging agencies to secure their systems.
BleepingComputer
2026-05-29
First public PoC released
Proof of Concept for CVE-2026-0257 was made public, increasing risk of exploitation.
BleepingComputer
2026-06-01
Multiple intrusions reported
Arctic Wolf Labs reported several attacks traced back to the exploitation of CVE-2026-0257.
Cybersecuritynews
2026-07-21
Ongoing exploitation confirmed
Arctic Wolf Labs confirmed that exploitation of CVE-2026-0257 leading to Qilin ransomware deployment is ongoing.
BleepingComputer

Community

Browse all →