Qilin ransomware affiliates are exploiting a critical Palo Alto VPN flaw to gain access to corporate networks and deploy ransomware, according to Arctic Wolf Labs.
The vulnerability, CVE-2026-0257, affects PAN-OS GlobalProtect portal and gateway products. Attackers can bypass authentication controls and establish an unauthorised VPN connection to vulnerable devices.
Arctic Wolf investigated several June 2026 intrusions that began with CVE-2026-0257 exploitation and ended with Qilin ransomware encrypting systems across the victim’s domain.
Attackers Use the Palo Alto VPN Flaw for Initial Access
Palo Alto Networks released patches for CVE-2026-0257 on 13 May. The company also warned that attackers had started exploiting unpatched PAN-OS devices.
Rapid7 had already observed attacks against numerous customers from 17 May.
The flaw lets attackers bypass security restrictions on GlobalProtect portals and gateways. They can then connect to the VPN without valid credentials.
The US Cybersecurity and Infrastructure Security Agency added CVE-2026-0257 to its Known Exploited Vulnerabilities catalogue on 29 May. It gave federal agencies three days to secure affected GlobalProtect VPN instances.
Qilin Affiliates Deploy Ransomware After Breaches
Arctic Wolf found several attack patterns after the initial VPN compromise.
Some attackers moved quickly and focused on encryption. Others conducted broader double-extortion operations, which combine ransomware encryption with data theft and extortion threats.
These differences suggest that multiple affiliates may use CVE-2026-0257 under Qilin’s ransomware-as-a-service model.
Arctic Wolf assesses with moderate confidence that attacks involving the Palo Alto VPN flaw remain ongoing. The company based that assessment on extensive scanning activity and the tendency for ransomware-as-a-service groups to share proven exploits among affiliates.
Thousands of GlobalProtect Instances Remain Exposed
Shadowserver tracks more than 167,000 GlobalProtect VPN instances exposed to the internet. Shodan has identified more than 172,000 IP addresses with a GlobalProtect fingerprint.
Those figures do not show how many organisations have already installed patches. They also include potential honeypots and other non-production systems.
However, organisations should treat exposed and unpatched GlobalProtect devices as a priority because attackers already use the vulnerability in ransomware attacks.
Qilin Continues to Target Major Organisations
Qilin emerged in August 2022 under the name Agenda. The group has since claimed more than 2,000 victims on its dark web leak site.
Its alleged victims include Nissan, Yangfeng, Asahi, Synnovis, Lee Enterprises, and Australia’s Court Services Victoria.
Palo Alto Networks serves more than 70,000 customers worldwide, including many major US banks and 90% of Fortune 10 companies.


0 responses to “Palo Alto VPN Flaw Fuels Qilin Ransomware Attacks”