Attackers behind the Qilin ransomware have been exploiting a high-severity vulnerability in Palo Alto Networks' PAN-OS to gain initial access to victim systems. The flaw, identified as CVE-2026-0257, is an authentication bypass issue that affects the portal and gateway, with a CVSS score of 7.8. This vulnerability was exploited in multiple intrusions investigated by Arctic Wolf Labs in June 2026, resulting in the deployment of Qilin ransomware. The fact that this vulnerability is being actively exploited1 highlights the need for immediate attention from organizations using affected PAN-OS versions. The exploitation of this vulnerability allows threat actors to bypass authentication mechanisms, gaining unauthorized access to sensitive systems. This matters to security practitioners because the active exploitation of CVE-2026-0257 necessitates prompt patching to prevent similar attacks, underscoring the importance of timely vulnerability management.
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
⚠️ Critical Alert
Why This Matters
CVE-2026-0257 is in active discussion involving Palo Alto — exploitation status determines whether this is patch-now or monitor.
References
- The Hacker News. (2026, July 21). Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access. *The Hacker News*. https://thehackernews.com/2026/07/qilin-ransomware-attackers-exploit-pan.html
Original Source
The Hacker News
Read original →