
Security researchers have discovered that the Qilin ransomware gang is exploiting a critical vulnerability in Palo Alto Networks’ GlobalProtect VPN product to break into business networks. The flaw, CVE-2026-0257, allows attackers to bypass the VPN’s authentication entirely — meaning they can connect to a company’s internal network from anywhere on the internet without a valid username or password. Once inside, they install ransomware that encrypts business files and, in many cases, steals data first to use as additional leverage when demanding payment.
Arctic Wolf Labs, which investigated multiple ransomware incidents in June and July 2026, found that Qilin affiliates move quickly after gaining access: they harvest saved credentials, spread to as many systems as possible using standard remote-access tools, wipe Windows event logs to erase their tracks, and then trigger encryption across the network. Some attacks focused only on encrypting files while others also exfiltrated data beforehand — suggesting multiple Qilin affiliates are using this same entry point with different approaches.
How to check if you’re affected
Affected versions of Palo Alto Networks PAN-OS include 10.2, 11.1, 11.2, and 12.1, specifically when the GlobalProtect portal or gateway feature has authentication override cookies enabled. Your IT team can check by reviewing the Palo Alto security advisory for CVE-2026-0257 in the firewall management console, or by verifying the installed PAN-OS firmware version against the patched builds published by Palo Alto. If your organization uses Palo Alto GlobalProtect VPN and has not applied the available patches for affected versions, this should be treated as urgent — attackers are actively scanning for vulnerable devices.
