Qilin ransomware crew is breaking into Palo Alto VPNs through an unpatched flaw

Arctic Wolf says multiple Qilin affiliates are exploiting CVE-2026-0257 in Palo Alto Networks firewalls to encrypt whole networks. Over 167,000 VPN instances remain exposed online.

ThreatVectr Newsdesk· 3 min read
Photoreal editorial shot of a dimly lit server room with a rack-mounted enterprise firewall appliance glowing red on its status LEDs, blue network cables tangle
Share

Key points

  • Arctic Wolf Labs said on Monday that Qilin ransomware affiliates are exploiting a critical Palo Alto Networks flaw, CVE-2026-0257, to break into corporate networks.
  • Palo Alto Networks patched the GlobalProtect authentication bypass on May 13, 2026, after Rapid7 spotted active exploitation from May 17.
  • The U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities list on May 29 and gave federal agencies three days to fix it.
  • Shadowserver counts more than 167,000 GlobalProtect VPN instances still reachable from the public internet.
  • Qilin has named over 2,000 victims on its dark web leak site since surfacing in August 2022, including Nissan, Asahi and pathology firm Synnovis.

A Russian-speaking ransomware crew called Qilin is breaking into company networks by abusing a serious flaw in Palo Alto Networks firewalls, according to cybersecurity firm Arctic Wolf.

Qilin runs what the industry calls ransomware-as-a-service, meaning the core gang builds the file-locking malware and rents it out to other criminals (called affiliates) who do the actual break-ins and split the profits. The group first appeared in August 2022 under the name Agenda. Its leak site now lists more than 2,000 victims, among them carmaker Nissan, parts supplier Yangfeng, Japanese brewer Asahi, UK pathology firm Synnovis, publisher Lee Enterprises and Australia's Court Services Victoria.

The flaw the gang is using is tracked as CVE-2026-0257. It sits in GlobalProtect, the remote-access VPN that Palo Alto Networks customers use to let staff log in from home. In plain terms, the bug lets an attacker skip the login check entirely and set up their own VPN connection into the corporate network, as if they were an employee.

Palo Alto Networks issued a fix on May 13, 2026. The company said at the time it had seen "limited exploit attempts on unpatched PAN-OS devices". Security firm Rapid7 then reported exploitation across many of its customers from May 17. On May 29, CISA added the bug to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch within three days.

How are the criminals getting in?

They are hitting the firewall directly over the internet. Because the flaw bypasses the login screen on GlobalProtect, an attacker only needs to find an unpatched device and send a crafted request. From there they establish a VPN tunnel and move inside the network.

Arctic Wolf, first reported by BleepingComputer, said it investigated several separate intrusions in June 2026 that all started with CVE-2026-0257 exploitation and ended with Qilin ransomware encrypting entire Windows domains. In some cases the attackers went straight to encryption. In others they stole data first and threatened to leak it, the tactic known as double extortion. That mix suggests different affiliates are running their own playbooks under the Qilin banner.

The exposure is large. Internet scanner Shadowserver tracks more than 167,000 GlobalProtect instances reachable online. Shodan, a similar service, sees over 172,000. Some will be patched, some will be honeypots set up to lure attackers, but the raw numbers show how much attack surface is out there. Palo Alto Networks says its products are used by more than 70,000 customers, including most large U.S. banks and 90% of the Fortune 10.

Arctic Wolf's own assessment is blunt: the attacks are "likely ongoing" and the scanning for vulnerable devices continues.

For ordinary people, the practical impact shows up later. If your bank, hospital or airline goes quiet, cancels appointments or asks you to reset passwords in the coming weeks, this is the kind of intrusion that sits behind it. Watch for breach notification emails from services you use, and be wary of unexpected calls or messages claiming to be from an affected company: criminals often follow ransomware attacks with fraud attempts aimed at customers.

© 2026 Threat Vectr