Arctic Wolf researchers warn that the Qilin ransomware gang is exploiting the critical PAN-OS GlobalProtect vulnerability CVE-2026-0257 to compromise corporate networks.
CVE-2026-0257 is a PAN-OS authentication bypass vulnerability affecting GlobalProtect portals and gateways.
Palo Alto Networks addressed the vulnerability on May 13. Two weeks later, cybersecurity firm Rapid7 confirmed active exploitation across multiple customer environments. In early June, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) catalog.
The vulnerability affects the GlobalProtect portal and gateway components of Palo Alto Networks PAN-OS, allowing attackers to bypass authentication and establish unauthorized VPN connections. The vulnerabilities do not affect Panorama or Cloud NGFW deployments.
“Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.” reads the advisory.
Arctic Wolf warns that the Qilin ransomware gang is exploiting the critical PAN-OS GlobalProtect vulnerability CVE-2026-0257 to compromise corporate networks. The flaw allows attackers to bypass authentication and establish unauthorized VPN sessions on unpatched devices. Palo Alto Networks released patches on May 13 and confirmed exploitation attempts against systems that had not applied updates or mitigations.
Arctic Wolf Labs has observed several attacks in which threat actors exploited CVE-2026-0257 to gain initial access and deploy Qilin ransomware across entire Windows domains. Investigators found evidence that multiple Qilin affiliates are actively abusing the flaw to compromise organizations, making unpatched PAN-OS GlobalProtect devices a high-priority target for ransomware operations.
“Arctic Wolf investigated multiple distinct intrusions during June 2026 that resulted in Qilin ransomware deployment, all originating from exploitation of CVE-2026-0257 against Palo Alto Networks firewall appliances.” reads the report published by Arctic Wolf. “Post-exploitation tradecraft varied across intrusions, from rapid encryption-only operations to full double-extortion, possibly suggesting multiple affiliates operating under the Qilin ransomware-as-a-service (RaaS) umbrella.”
Arctic Wolf found that attacks exploiting CVE-2026-0257 followed a common initial pattern but diverged after compromise. Threat actors consistently used the same entry point, ransomware staging paths, PsExec execution, and registry persistence. However, some attacks quickly encrypted entire environments without stealing data, while others involved extensive reconnaissance, deployment of remote-access tools such as AnyDesk, Ngrok, and LogMeIn, large-scale credential theft, and data exfiltration to cloud services before ransomware execution, reflecting the varied tactics of Qilin RaaS affiliates.
After exploiting CVE-2026-0257, the attackers established VPN sessions from Kali Linux systems, then quickly secured persistent access using registry Run keys, scheduled tasks, and remote administration tools such as AnyDesk, Ngrok, LogMeIn, and MeshAgent. They harvested credentials by dumping LSASS memory and extracting the Active Directory database (NTDS), enabling lateral movement with PsExec, RDP, and compromised administrator accounts.
The operators scanned networks with SoftPerfect Network Scanner and NetExec, cleared Windows event logs, and in some cases disabled Microsoft Defender before deploying ransomware. Several intrusions also involved data theft using Rclone, ProtonDrive, FileZilla, and MEGA cloud storage, while others focused solely on rapid encryption.
The ransomware payload, typically named win.exe, was staged in C:\PerfLogs, executed with password-protected parameters, and encrypted files using unique extensions assigned to each campaign.

“The variability in post-exploitation tradecraft, from encryption-only operations to full double-extortion, shows that perimeter compromise is the critical point for defenders. After exploitation succeeds, the impact depends on the affiliate’s goals and timeline, but domain compromise and ransomware deployment are consistent.” concludes the report. “Arctic Wolf Labs assesses with moderate confidence that intrusions leveraging CVE-2026-0257 and leading to Qilin ransomware deployment are likely ongoing. This assessment is based on the extensive scanning activity observed and the RaaS model’s tendency to distribute successful exploits among multiple affiliates.”
Qilin ransomware operation has been active since 2022, it has become one of the most active RaaS groups in 2025, claiming over 40 victims monthly and peaking at 100 in June.
The group enables affiliates to deploy customized ransomware payloads against targeted organizations. Qilin uses double-extortion tactics, encrypting data while threatening to leak it via Tor-based portals. The group has targeted multiple sectors worldwide, including healthcare, manufacturing, and finance, leveraging phishing and known vulnerabilities.
In October 2025, Resecurity’s researchers detailed how the Qilin RaaS group relies on global bulletproof hosting networks to support its extortion operations.
In early October, DragonForce, LockBit, and Qilin formed a ransomware alliance to boost attack effectiveness, marking a major shift in the cyber threat landscape. Ransomware groups DragonForce, LockBit, and Qilin formed a strategic alliance to enhance their attack capabilities, signaling an evolving cyber threat landscape. The alliance aims at sharing tools and infrastructure to enhance attack effectiveness.
At the end of March, Qilin Ransomware group allegedly breached the chemical manufacturing giant Dow Inc.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)