securityonline.info 7/21/2026, 3:32:25 AM · external

Qilin ransomware exploits CVE-2026-0257 in Palo Alto firewall

Qilin ransomware exploits CVE-2026-0257 in Palo Alto firewall
Developing story vulnerability 16 articles tracked
Active exploitation of Palo Alto GlobalProtect VPN flaw CVE-2026-0257
CyberSIXT Evidence Panel
Primary Source arcticwolf.com
CISA KEV Listed in KEV
Patch Patch Available
Threat Actor
Qilin

IN June 2026, Arctic Wolf Labs identified multiple ransomware incidents linked to the Qilin ransomware, attributed to an exploitation of the CVE-2026-0257 vulnerability in Palo Alto Networks' GlobalProtect firewall. This authentication bypass allowed attackers to gain VPN access without valid credentials, leading to domain-wide encryption of data. The Qilin operation employs a ransomware-as-a-service model with evidence suggesting multiple affiliates are involved.

Victims faced not only encryption but also data exfiltration in double-extortion cases. No arrests have been reported, and ongoing exploitation is expected. Recommendations for protection include updating affected systems, monitoring suspicious VPN sessions, and recognizing early signs of intrusion to prevent encryption.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline