A Critical Palo Alto VPN Bug is Being Exploited by Ransomware Gangs, Putting Thousands at Risk
A critical vulnerability in Palo Alto Networks’ PAN-OS software has been exploited by the Qilin ransomware gang to breach corporate networks, putting thousands of organizations and their sensitive data at risk. The bug, known as CVE-2026-0257, was identified back in May and patched by Palo Alto Networks on May 13, but it appears that many organizations have yet to apply the fix.
The vulnerability allows attackers to bypass security restrictions and establish an unauthorized VPN connection, giving them access to sensitive areas of a network. The Qilin ransomware gang has been using this exploit to encrypt entire domains, resulting in significant downtime and financial losses for affected organizations. Arctic Wolf Labs, a cybersecurity company, revealed that it had observed multiple cases where the Qilin gang exploited CVE-2026-0257 to gain unauthorized access to networks.
The bug was added to the US Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerability catalog on May 29, with CISA ordering federal agencies to secure their GlobalProtect VPN instances within three days. Despite this warning, it appears that many organizations have yet to take action, leaving themselves vulnerable to attacks.
The Qilin ransomware gang has a history of targeting high-profile organizations, including Nissan, Yangfeng, Asahi, and Synnovis. Palo Alto Networks’ products and services are used by over 70,000 customers worldwide, including most of the largest US banks and 90% of Fortune 10 companies. The fact that this bug is being exploited by a ransomware gang raises serious concerns about the potential for widespread damage.
It’s essential to note that not all GlobalProtect VPN instances have been compromised yet. However, with over 167,000 exposed online and 172,000 IPs with a GlobalProtect fingerprint, the risk of exploitation remains high. Organizations using Palo Alto Networks’ products must take immediate action to patch their systems and protect themselves against this critical vulnerability.
The takeaway for security teams is clear: they need to be proactive in testing their defenses and identifying vulnerabilities before attackers do. By conducting regular breach and attack simulation tests, organizations can strengthen their security posture and prevent attacks like these from succeeding. As the Picus whitepaper demonstrates, this type of testing can help identify weaknesses in SIEM and EDR rules, ensuring that threats don’t slip through detection. It’s time for organizations to take a proactive approach to cybersecurity and prioritize patching and testing before it’s too late.
Source: Bleeping Computer — 2026-07-21