ZeroHour
Security Affairspublished ()ingested @securityaffairs

Qilin Ransomware Affiliates Abuse CVE-2026

criticalRansomware exploited in the wildimportance 60CVE-2026-0257

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-0257
Authentication Bypass in Palo Alto Networks PAN-OS GlobalProtect Portal and Gateway

CVE-2026-0257 is an authentication bypass in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS that allows a remote, unauthenticated attacker to defeat security restrictions and establish an unauthorized VPN connection; incident reporting indicates it involves forged VPN cookies (CWE-565). An attacker who succeeds gains the network access of a legitimate remote-access user, and Qilin ransomware affiliates have been using this flaw as their initial access vector. Any organization running PAN-OS with the GlobalProtect portal or gateway enabled is in scope, including Siemens RUGGEDCOM APE1808 appliances that run PAN-OS, while Panorama and Cloud NGFW are explicitly not affected. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2026-05-29 with ransomware use known, EPSS assigns it a 93.9% probability of exploitation within 30 days (100th percentile), and Rapid7 has documented attacks against multiple customers.

Do: Upgrade PAN-OS to the fixed release specified in the Palo Alto Networks security advisory, and check Siemens' guidance if you operate RUGGEDCOM APE1808 appliances. Review GlobalProtect portal/gateway logs for forged VPN cookies and unauthorized VPN sessions, and hunt for Qilin ransomware indicators on hosts reachable through the VPN. If patching cannot happen immediately, restrict internet exposure of the GlobalProtect portal and gateway; federal agencies must apply mitigations per BOD 22-01 given the KEV listing.

7.895% KEV ransomware
  • Palo Alto Networks PAN-OS (GlobalProtect portal and gateway)
  • Palo Alto Networks Prisma Access Listed in CPE data; affected status not detailed in source description, confirm with vendor advisory
  • Siemens RUGGEDCOM APE1808 firmware
massOn the order of hundreds of thousands of internet-exposed GlobalProtect portals/devices (mid-six figures)
Full article801 words · extracted from securityaffairs.com · click to collapse

Qilin ransomware exploits the PAN-OS GlobalProtect flaw CVE-2026-0257 to gain unauthorized VPN access to unpatched networks.

Arctic Wolf researchers warn that the Qilin ransomware gang is exploiting the critical PAN-OS GlobalProtect vulnerability CVE-2026-0257 to compromise corporate networks.

CVE-2026-0257 is a PAN-OS authentication bypass vulnerability affecting GlobalProtect portals and gateways.

Palo Alto Networks addressed the vulnerability on May 13. Two weeks later, cybersecurity firm Rapid7 confirmed active exploitation across multiple customer environments. In early June, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw CVE-2026-0257 to its Known Exploited Vulnerabilities (KEV) catalog.

The vulnerability affects the GlobalProtect portal and gateway components of Palo Alto Networks PAN-OS, allowing attackers to bypass authentication and establish unauthorized VPN connections. The vulnerabilities do not affect Panorama or Cloud NGFW deployments.

“Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.” reads the advisory.

Arctic Wolf warns that the Qilin ransomware gang is exploiting the critical PAN-OS GlobalProtect vulnerability CVE-2026-0257 to compromise corporate networks. The flaw allows attackers to bypass authentication and establish unauthorized VPN sessions on unpatched devices. Palo Alto Networks released patches on May 13 and confirmed exploitation attempts against systems that had not applied updates or mitigations.

Arctic Wolf Labs has observed several attacks in which threat actors exploited CVE-2026-0257 to gain initial access and deploy Qilin ransomware across entire Windows domains. Investigators found evidence that multiple Qilin affiliates are actively abusing the flaw to compromise organizations, making unpatched PAN-OS GlobalProtect devices a high-priority target for ransomware operations.

“Arctic Wolf investigated multiple distinct intrusions during June 2026 that resulted in Qilin ransomware deployment, all originating from exploitation of CVE-2026-0257 against Palo Alto Networks firewall appliances.” reads the report published by Arctic Wolf. “Post-exploitation tradecraft varied across intrusions, from rapid encryption-only operations to full double-extortion, possibly suggesting multiple affiliates operating under the Qilin ransomware-as-a-service (RaaS) umbrella.”

Arctic Wolf found that attacks exploiting CVE-2026-0257 followed a common initial pattern but diverged after compromise. Threat actors consistently used the same entry point, ransomware staging paths, PsExec execution, and registry persistence. However, some attacks quickly encrypted entire environments without stealing data, while others involved extensive reconnaissance, deployment of remote-access tools such as AnyDesk, Ngrok, and LogMeIn, large-scale credential theft, and data exfiltration to cloud services before ransomware execution, reflecting the varied tactics of Qilin RaaS affiliates.

After exploiting CVE-2026-0257, the attackers established VPN sessions from Kali Linux systems, then quickly secured persistent access using registry Run keys, scheduled tasks, and remote administration tools such as AnyDesk, Ngrok, LogMeIn, and MeshAgent. They harvested credentials by dumping LSASS memory and extracting the Active Directory database (NTDS), enabling lateral movement with PsExec, RDP, and compromised administrator accounts.

The operators scanned networks with SoftPerfect Network Scanner and NetExec, cleared Windows event logs, and in some cases disabled Microsoft Defender before deploying ransomware. Several intrusions also involved data theft using Rclone, ProtonDrive, FileZilla, and MEGA cloud storage, while others focused solely on rapid encryption.

The ransomware payload, typically named win.exe, was staged in C:\PerfLogs, executed with password-protected parameters, and encrypted files using unique extensions assigned to each campaign.

“The variability in post-exploitation tradecraft, from encryption-only operations to full double-extortion, shows that perimeter compromise is the critical point for defenders. After exploitation succeeds, the impact depends on the affiliate’s goals and timeline, but domain compromise and ransomware deployment are consistent.” concludes the report. “Arctic Wolf Labs assesses with moderate confidence that intrusions leveraging CVE-2026-0257 and leading to Qilin ransomware deployment are likely ongoing. This assessment is based on the extensive scanning activity observed and the RaaS model’s tendency to distribute successful exploits among multiple affiliates.”

Qilin ransomware operation has been active since 2022, it has become one of the most active RaaS groups in 2025, claiming over 40 victims monthly and peaking at 100 in June.

The group enables affiliates to deploy customized ransomware payloads against targeted organizations. Qilin uses double-extortion tactics, encrypting data while threatening to leak it via Tor-based portals. The group has targeted multiple sectors worldwide, including healthcare, manufacturing, and finance, leveraging phishing and known vulnerabilities.

In October 2025, Resecurity’s researchers detailed how the Qilin RaaS group relies on global bulletproof hosting networks to support its extortion operations.

In early October, DragonForceLockBit, and Qilin formed a ransomware alliance to boost attack effectiveness, marking a major shift in the cyber threat landscape. Ransomware groups DragonForce, LockBit, and Qilin formed a strategic alliance to enhance their attack capabilities, signaling an evolving cyber threat landscape. The alliance aims at sharing tools and infrastructure to enhance attack effectiveness. 

At the end of March, Qilin Ransomware group allegedly breached the chemical manufacturing giant Dow Inc. 

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/195730/cyber-crime/qilin-ransomware-affiliates-abuse-cve-2026-0257-to-gain-unauthorized-vpn-access.html