A critical PAN-OS GlobalProtect authentication bypass is now confirmed to be a live ransomware entry point, with Qilin affiliates using it to reach domain-wide encryption. UK teams running exposed Palo Alto network security solutions should treat unpatched appliances as an active breach risk, not a theoretical one.
View the data behind this chart
| Phase | Starts (week) | Duration (weeks) |
|---|---|---|
| PAN-OS patch released | 0 | 1 |
| Active exploitation begins | 1 | 1 |
| CISA KEV listing, 3-day… | 2 | 1 |
| Qilin domain-wide… | 4 | 3 |
| Arctic Wolf: intrusions… | 9 | 1 |
What Arctic Wolf found
Cybersecurity firm Arctic Wolf says it investigated multiple distinct intrusions during June 2026 that all traced back to exploitation of CVE-2026-0257 against Palo Alto Networks firewall appliances, culminating in domain-wide Qilin ransomware encryption. Post-exploitation behaviour varied from rapid encryption-only runs to full double-extortion campaigns, which Arctic Wolf says points to multiple separate Qilin affiliates independently working the same flaw under the group's ransomware-as-a-service model.
Arctic Wolf assesses with moderate confidence that exploitation is ongoing, citing continued scanning activity and the RaaS model's habit of spreading a working exploit across many affiliates once one has proven it works.
The technical flaw, in plain terms
CVE-2026-0257 is an authentication bypass in the GlobalProtect portal and gateway components of PAN-OS, carrying a CVSSv4 score of 7.8 (High). The root cause is a configuration error: the same TLS certificate is reused for HTTPS services and for encrypting authentication override cookies, and the decryption process does not verify a signature. That combination lets an attacker forge a valid override cookie and open a fully authenticated VPN session without ever supplying credentials.
Palo Alto Networks patched the bug on 13 May 2026, but exploitation began just four days later, on 17 May, and the vendor has since raised the advisory to its highest urgency label after confirming limited exploit attempts against unpatched, unmitigated devices.
Why this matters for UK infrastructure buyers
Palo Alto's products sit behind more than 70,000 organisations worldwide, including most large US banks and 90% of the Fortune 10 — a customer base with a heavy overlap into the kind of regulated, high-value UK operators (finance, energy, healthcare, logistics) that Qilin has already shown appetite for. Shadowserver currently tracks over 167,000 GlobalProtect VPN instances exposed to the internet, and Shodan counts more than 172,000 IPs carrying a GlobalProtect fingerprint. Nobody publicly knows how many of those are honeypots or already patched, which means the real attack surface could be smaller — or could still include a meaningful slice of unremediated UK estate.
CISA added CVE-2026-0257 to its Known Exploited Vulnerabilities catalogue on 29 May 2026, giving US federal agencies just three days to secure their GlobalProtect instances. UK organisations have no equivalent binding deadline, but the KEV listing is a reliable signal that exploitation is proven, automated and being used for real intrusions rather than academic research.

Qilin's pattern: VPN gateways are the preferred door
Qilin surfaced in August 2022 under the name Agenda and has since claimed more than 2,000 victims on its dark web leak site, including Nissan, Yangfeng, Asahi, pathology provider Synnovis, publisher Lee Enterprises and Australia's Court Services Victoria. The group has a documented history of exploiting VPN authentication bypass flaws specifically, having previously targeted Fortinet devices before turning to CVE-2026-0257. This is not opportunistic; it is a repeatable playbook of scanning for unpatched remote-access gateways, breaking in via authentication bypass, and moving straight to ransomware protection strategies-defeating domain-wide encryption.
For buyers, the lesson from this pattern is that any internet-facing VPN concentrator is now a standing target, and patch latency on that single device class carries outsized risk compared with almost any other part of the estate.
Immediate steps for exposed estates
Organisations unable to patch immediately should consult Palo Alto Networks' official advisory for interim mitigation guidance applicable to their specific GlobalProtect deployment. Interim steps are not a substitute for applying the fix, but acting on vendor guidance now closes the window Qilin affiliates are currently exploiting.
- •Patch PAN-OS to the fixed release immediately on all internet-facing GlobalProtect portals and gateways
- •If patching is delayed, consult Palo Alto Networks' advisory for interim mitigation options for your deployment
- •Audit which GlobalProtect instances are actually internet-exposed and whether any predate current vulnerability management services coverage
- •Assume compromise where devices were unpatched between 17 May and now, and hunt for lateral movement rather than trusting a clean scan
- •Loop in managed detection & response teams to watch for the rapid-encryption pattern Arctic Wolf describes
View the data behind this chart
| Shadowserver | Shodan | |
|---|---|---|
| Exposed instances | instance…167000 | instance…172000 |
The longer game: rethinking VPN as the front door
This is at least the third major VPN authentication bypass in recent memory to feed directly into Qilin ransomware deployments, following earlier Fortinet and Check Point incidents. Each case follows the same shape: a single credential-adjacent flaw in a remote-access gateway grants an attacker the same trust as a legitimate employee. For UK buyers reviewing architecture rather than just patch cadence, this repeated pattern is a strong argument for accelerating migrating from VPN to ZTNA, where access is brokered per-application rather than granted wholesale to a network segment the moment a cookie or credential is accepted. Understanding VPN vs. ZTNA for business trade-offs now, before the next gateway flaw appears, is cheaper than remediating after a Qilin encryption event, and it fits the broader shift documented in how how ransomware attacks have evolved this year toward exploiting perimeter infrastructure rather than phishing users directly.
- 01BleepingComputer — Critical Palo Alto VPN bug now exploited by Qilin ransomware gang · 21 July 2026
- 02The Hacker News — Palo Alto warns of active exploitation · 1 June 2026
- 03The Register — Palo Alto VPN bug graduates from advisory to active exploitation · 1 June 2026
- 04TechRadar Pro — PAN-OS sees authentication bypass under attack from hackers · 1 June 2026
- 05IBM X-Force — Palo Alto, Fortinet secure remote access gateway VPN compromise advisory · 1 June 2026
- 06BleepingComputer — Critical Fortinet flaws now exploited in Qilin ransomware attacks · 1 January 2026
