Critical Palo Alto VPN Bug Exploited by Qilin Ransomware Gang, Puts Thousands at Risk
A severe vulnerability in Palo Alto Networks’ GlobalProtect Virtual Private Network (VPN) software has been exploited by the notorious Qilin ransomware gang to breach victims’ networks. The flaw, known as CVE-2026-0257, was patched by Palo Alto on May 13, but it appears that many organizations have yet to apply the fix.
The Qilin gang is a well-known Ransomware-as-a-Service (RaaS) operation that has claimed responsibility for over 2,000 victims since its emergence in August 2022. The group’s targets include some of the world’s largest companies, including automotive giants Nissan and Yangfeng, Japanese beer giant Asahi, pathology services provider Synnovis, publishing giant Lee Enterprises, and Australia’s Court Services Victoria.
According to cybersecurity company Arctic Wolf, multiple cases have been observed where threat actors exploited CVE-2026-0257 in attacks that led to domain-wide Qilin ransomware encryption. The evidence collected suggests that multiple Qilin affiliates are actively exploiting this flaw to breach targets’ networks. “Arctic Wolf investigated multiple distinct intrusions during June 2026 that resulted in Qilin ransomware deployment, all originating from exploitation of CVE-2026-0257 against Palo Alto Networks firewall appliances,” the company said.
The vulnerability allows attackers to bypass security restrictions and establish an unauthorized VPN connection. This can grant them access to sensitive data and systems within a network. Palo Alto warned at the time of the patch release that limited exploit attempts had been observed on unpatched devices without mitigations applied.
The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-0257 to its Known Exploited Vulnerability catalog on May 29, ordering federal agencies to secure their GlobalProtect VPN instances within three days. However, it appears that many organizations have yet to take action.
Internet threat watchdog Shadowserver tracks over 167,000 GlobalProtect VPN instances exposed online, while Shodan found over 172,000 IPs with a GlobalProtect fingerprint. While there is no information on how many of these are honeypots or have already been patched against CVE-2026-0257 attacks, the sheer number of potentially vulnerable devices raises concerns.
The exploitation of this vulnerability highlights the importance of regular security updates and patches. Palo Alto’s products and services are used by over 70,000 customers worldwide, including most of the largest US banks and 90% of Fortune 10 companies. It is essential for these organizations to ensure that their systems are up-to-date and that their users are aware of the risks associated with this vulnerability.
In light of this incident, security teams should prioritize testing every layer of their defenses before attackers do. A recent study found that security teams log 54% of successful attacks and alert on just 14%, leaving the rest to move through their environment unseen. Regular breach and attack simulation tests can help identify vulnerabilities and ensure that SIEM and EDR rules are effective in detecting threats.
Source: Bleeping Computer — 2026-07-21