
PALO Alto Networks has confirmed that the Qilin ransomware group is actively exploiting CVE‑2026‑0257. The flaw in PAN‑OS lets attackers bypass GlobalProtect VPN authentication even though a patch was released on 13 May 2026.
The vulnerability carries a CVSS score of 7.8 and stems from an authentication bypass that allows forged cookies to be accepted on GlobalProtect portals and gateways. This grants VPN access without the need for valid credentials.
Security researchers at Arctic Wolf Labs observed Qilin affiliates using the flaw to establish illicit VPN sessions. After gaining access they deployed ransomware and stole data for double‑extortion schemes.
The flaw was added to the CISA Known Exploited Vulnerabilities catalogue on 29 May 2026 and has been seen in multiple customer environments. Rapid7 confirmed early exploitation shortly after the vulnerability was disclosed.
Organisations should apply the PAN‑OS update released in May and review GlobalProtect logs for anomalous login patterns. Enforcing multi‑factor authentication for VPN access is also strongly advised.
Security teams should monitor for the indicators of compromise shared by Unit 42 and update incident‑response playbooks to include VPN‑focused scenarios. As a temporary measure they should consider restricting VPN connections to trusted IP ranges.