A critical vulnerability in Palo Alto Networks' PAN-OS, identified as CVE-2026-0257, is being exploited by Qilin ransomware affiliates to bypass authentication and gain unauthorized access to corporate VPNs. This flaw, which affects GlobalProtect portals and gateways, was addressed by Palo Alto on May 13, but active exploitation has been confirmed by Rapid7 across multiple customer environments. The Qilin ransomware gang is leveraging this vulnerability to compromise unpatched networks, highlighting the importance of prompt patching. The exploitation of CVE-2026-0257 allows attackers to access sensitive data and disrupt operations, making it a significant concern for organizations using affected Palo Alto products1. So what matters to practitioners is that they must prioritize patching this vulnerability to prevent Qilin ransomware affiliates from gaining a foothold in their networks.
Qilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN Access
⚠️ Critical Alert
Why This Matters
CVE-2026-0257 is in active discussion involving Palo Alto — exploitation status determines whether this is patch-now or monitor.
References
- SecurityAffairs. (2026, July 21). Qilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN Access. SecurityAffairs. https://securityaffairs.com/195730/cyber-crime/qilin-ransomware-affiliates-abuse-cve-2026-0257-to-gain-unauthorized-vpn-access.html
Original Source
SecurityAffairs
Read original →