Skip to main content
Emerging ThreatsMalware & Ransomware

Qilin Ransomware Gang Exploits Palo Alto VPN Bug in Ongoing Attacks

IT staff work in a network operations room with rows of equipment and technology.

CVE-2026-0257 — a critical PAN-OS GlobalProtect authentication bypass — is now being actively exploited by the Qilin ransomware gang, according to cybersecurity company Arctic Wolf.

CVE-2026-0257 and Palo Alto Networks' May 13 patch

Palo Alto Networks addressed CVE-2026-0257 on May 13, describing it as a flaw that lets an attacker bypass security restrictions and "establish an unauthorized VPN connection" through the GlobalProtect portal and gateway in PAN-OS software. The vendor warned that it had "become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied." Rapid7 reported seeing exploitation against numerous customers beginning on May 17.

Arctic Wolf Labs: Multiple Qilin intrusions in June 2026

Arctic Wolf Labs reported investigating "multiple distinct intrusions during June 2026 that resulted in Qilin ransomware deployment, all originating from exploitation of CVE-2026-0257 against Palo Alto Networks firewall appliances." The company said post-exploitation tradecraft varied between intrusions, ranging "from rapid encryption-only operations to full double-extortion, possibly suggesting multiple affiliates operating under the Qilin ransomware-as-a-service (RaaS) umbrella."

Arctic Wolf assessed "with moderate confidence that intrusions leveraging CVE-2026-0257 and leading to Qilin ransomware deployment are likely ongoing," citing extensive scanning activity and the RaaS model's tendency to distribute successful exploits among affiliates.

CISA listing and the three-day federal order

The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-0257 to its Known Exploited Vulnerability catalog on May 29 and issued a directive for federal agencies to secure their GlobalProtect VPN instances within three days. The catalog listing formalizes the vulnerability as a prioritized, actively exploited risk for government networks.

Exposure tallies from Shadowserver and Shodan

Internet monitoring groups reported large numbers of GlobalProtect endpoints exposed online. Shadowserver now tracks over 167,000 GlobalProtect VPN instances, while Shodan found over 172,000 IPs with a GlobalProtect fingerprint. The trackers do not, the reporting notes, indicate how many of those hosts are honeypots or have already been patched against CVE-2026-0257 exploitation.

Qilin's footprint and affected organizations

Qilin operates as a Ransomware-as-a-Service operation that surfaced in August 2022 under the "Agenda" name and has since claimed responsibility for more than 2,000 victims on its dark web leak site. Named victims listed by the group include Nissan and Yangfeng, Asahi, Synnovis, Lee Enterprises, and Australia's Court Services Victoria.

The reporting also highlights the extent of Palo Alto Networks' customer base: its products and services are used by over 70,000 customers worldwide, including most of the largest U.S. banks and 90% of Fortune 10 companies—underscoring the potential scale of impact for an exploitable GlobalProtect flaw.

What this means for security teams, federal agencies, and affected enterprises

  • Security teams and technologists: Arctic Wolf's account of varied post-exploitation behavior — from immediate encryption to full double-extortion — underscores that successful exploitation can lead to differing operational outcomes. The Picus whitepaper cited in the reporting also offers a stark metric: "Security teams log 54% of successful attacks and alert on just 14%." Teams that have not applied Palo Alto's May 13 updates or mitigations should prioritize verification.
  • Federal agencies and policymakers: CISA's May 29 listing and three-day remediation order make CVE-2026-0257 a near-term compliance priority for agencies operating GlobalProtect VPN instances.
  • Affected enterprises and procurement leaders: Given Qilin's history of claiming high-profile victims and Palo Alto's wide customer base, organizations that rely on GlobalProtect should validate patch status and monitor for signs of scanning activity or lateral movement consistent with the incidents Arctic Wolf describes.

Arctic Wolf's "moderate confidence" assessment that exploitation and follow-on ransomware deployments are likely ongoing, combined with CISA's expedited federal remediation mandate and the large number of exposed GlobalProtect endpoints reported by Shadowserver and Shodan, leaves a sharp, specific question for defenders: how many GlobalProtect instances remain unpatched since Palo Alto's May 13 fix? The timeline in the reporting — patch May 13, observed exploitation from May 17, CISA action May 29, and multiple Qilin-driven encryptions in June — frames that question as urgent.

Read the original report