A critical vulnerability in Palo Alto Networks' PAN-OS, identified as CVE-2026-0257, is being exploited by Qilin ransomware affiliates to bypass authentication and gain unauthorized access to corporate VPNs. This flaw, which affects GlobalProtect portals and gateways, was addressed by Palo Alto on May 13, but active exploitation has been confirmed by Rapid7 across multiple customer environments. The Qilin ransomware gang is leveraging this vulnerability to compromise unpatched networks, highlighting the importance of prompt patching. The exploitation of CVE-2026-0257 allows attackers to access sensitive data and disrupt operations, making it a significant concern for organizations using affected Palo Alto products1. So what matters to practitioners is that they must prioritize patching this vulnerability to prevent Qilin ransomware affiliates from gaining a foothold in their networks.