№202|04:02 PM ET
Independent reporting on technology, markets & policy
TechEchelon
№01 / Anchor·CYBERSECURITY

Qilin Ransomware Gang Exploits Critical Palo Alto GlobalProtect VPN Flaw in Active Attacks

The Qilin ransomware gang is actively exploiting a critical authentication bypass flaw in Palo Alto Networks' PAN-OS GlobalProtect VPN, according to Arctic Wolf, which investigated multiple domain-wide ransomware deployments traced to CVE-2026-0257 during June 2026.

SM
Sara Montes de Oca
JUL 21, 2026 · 01:01 PM ET · 2 MIN READ
via Wikipedia (Palo Alto Networks)

The Qilin ransomware group is actively exploiting a critical authentication bypass vulnerability in Palo Alto Networks' PAN-OS GlobalProtect VPN software, according to cybersecurity firm Arctic Wolf, which investigated multiple intrusions in June 2026 that ended in domain-wide ransomware encryption.

The vulnerability, tracked as CVE-2026-0257, allows an attacker to bypass security restrictions and establish an unauthorized VPN connection through the GlobalProtect portal and gateway, Palo Alto Networks warned when it first disclosed the flaw.

Palo Alto Networks patched CVE-2026-0257 on May 13. Rapid7 subsequently reported observing active exploitation against numerous customers beginning May 17, prompting Palo Alto to warn of "limited exploit attempts on unpatched PAN-OS devices without mitigations applied."

The U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerability catalog on May 29, ordering federal agencies to secure their GlobalProtect VPN instances within three days.

Arctic Wolf's Monday disclosure describes multiple distinct intrusions during June 2026, all originating from exploitation of CVE-2026-0257 against Palo Alto Networks firewall appliances. The firm assessed with moderate confidence that intrusions leveraging the flaw and leading to Qilin ransomware deployment are likely ongoing.

"Post-exploitation tradecraft varied across intrusions, from rapid encryption-only operations to full double-extortion, possibly suggesting multiple affiliates operating under the Qilin ransomware-as-a-service (RaaS) umbrella," Arctic Wolf said in its report.

The scale of the exposure is significant. Internet threat watchdog Shadowserver now tracks over 167,000 GlobalProtect VPN instances exposed online, while Shodan has identified over 172,000 IPs carrying a GlobalProtect fingerprint. How many of those devices remain unpatched or are honeypots is unknown.

Qilin first surfaced in August 2022 under the name "Agenda" and has since claimed more than 2,000 victims on its dark web leak site. Its roster of targets includes automotive manufacturers Nissan and Yangfeng, Japanese beer producer Asahi, pathology services provider Synnovis, publishing company Lee Enterprises, and Australia's Court Services Victoria.

Palo Alto Networks counts over 70,000 customers worldwide among its user base, including most of the largest U.S. banks and 90% of Fortune 10 companies — a footprint that makes unpatched GlobalProtect deployments a high-value target for ransomware affiliates seeking broad enterprise access.

Organizations running PAN-OS GlobalProtect that have not yet applied the May 13 patch face an elevated risk of compromise, particularly given the RaaS model's tendency to distribute proven exploits across multiple independent operators. Security teams are advised to verify patch status and review VPN logs for anomalous authentication activity.

SM
━ ABOUT THE REPORTER
Sara Montes de Oca

Sara Montes de Oca is the Editor in Chief of TechEchelon. Previously a correspondent and producer in Washington, D.C., covering business, finance, and politics.

More from Sara
● THE BRIEF · DAILY NEWSLETTER

Five stories every morning. Before the opening bell.

Written for readers who already know the basics — markets, AI, and the policy decisions that shape both.

Mon — Fri · 06:30 ET · Free

No spam · Unsubscribe anytime