The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf.
Palo Alto Networks addressed the vulnerability (CVE-2026-0257) on May 13 and warned that attackers had begun abusing it to breach corporate networks after Rapid7 reported observing it being exploited against numerous customers starting on May 17.
"GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection," the company warned at the time. "Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied."
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) also added the flaw to its Known Exploited Vulnerability catalog on May 29, ordering federal agencies to secure their GlobalProtect VPN instances within three days.
On Monday, Arctic Wolf Labs revealed that it observed multiple cases where threat actors exploited CVE-2026-0257 in attacks that led to domain-wide Qilin ransomware encryption, noting that evidence collected while investigating these incidents points to multiple Qilin affiliates actively exploiting this flaw to breach targets' networks.







