← All stories
● Covered by 2 sources · 2 reportsMedium impact

Qilin Ransomware Gang Exploits Patched PAN-OS VPN Vulnerability

🔄 Updated 1h ago — new reporting from The Hacker News

The Qilin ransomware gang is exploiting a critical flaw (CVE-2026-0257) in Palo Alto Networks' PAN-OS GlobalProtect to gain unauthorized access and deploy ransomware. Despite the vulnerability being patched on May 13, 2026, attacks have led to network breaches and data encryption. The U.S. CISA has urged federal agencies to secure their GlobalProtect instances immediately.

Key points

  • Qilin ransomware gang exploits CVE-2026-0257 in PAN-OS.
  • The vulnerability was patched by Palo Alto Networks on May 13, 2026.
  • CISA urges quick patching for federal GlobalProtect VPNs.
  • Exploitation includes bypassing authentication for VPN access.

Vulnerability Details

A critical authentication bypass vulnerability, CVE-2026-0257, in Palo Alto Networks' PAN-OS GlobalProtect, is actively being exploited by the Qilin ransomware group. The flaw allows attackers to establish unauthorized VPN connections.

Patch Release and Subsequent Exploitation

The vulnerability was addressed by Palo Alto Networks with a patch released on May 13, 2026. Despite this, attackers commenced exploitation as early as May 17, 2026, particularly targeting unpatched systems.

Arctic Wolf Labs reported multiple cases of CVE-2026-0257 being used for domain-wide ransomware deployments in June, with attackers exploiting enabling configurations such as authentication override cookies.

Security Advisories and Responses

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its known vulnerabilities catalog, mandating federal agencies to patch their systems by May 29, 2026.

Security experts have observed a variety of post-exploitation tactics, indicating a ransomware-as-a-service model involving multiple affiliates.

Industry Impact

This incident underscores the critical importance of timely patch management, particularly for vulnerabilities with active exploit activity. It highlights the persistent threat posed by ransomware groups leveraging unpatched software to compromise systems.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~39 min · 34 stories · Jul 21

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Attackers are using a patched vulnerability in PAN-OS to deploy Qilin ransomware. This exploitation allows unauthorized access to established VPN sessions, leading to data theft and system compromise.

The Qilin ransomware gang is exploiting a critical vulnerability (CVE-2026-0257) in Palo Alto Networks' PAN-OS GlobalProtect software. This exploitation allows unauthorized VPN connections, leading to significant network breaches and data encryption.