Qilin Ransomware Crews Break In Through Palo Alto Firewall Flaw

Arctic Wolf Labs says attackers used CVE-2026-0257, a now-patched authentication bypass in PAN-OS, to get inside networks before deploying Qilin ransomware in June 2026.

ThreatVectr Newsdesk· 3 min read
A photoreal editorial image of a server room corridor at night, one rack door slightly ajar with a soft red warning light spilling out, blue status LEDs on netw
Share

Key points

  • Arctic Wolf Labs reported multiple June 2026 intrusions that started with attackers exploiting a Palo Alto Networks firewall flaw.
  • The flaw, tracked as CVE-2026-0257, carries a severity score of 7.8 out of 10 and lets attackers skip the login step on the firewall's portal and gateway.
  • Palo Alto Networks has already released a patch, so the bug is fixed for anyone who updates.
  • After breaking in, the attackers installed Qilin ransomware, also known as Agenda, which scrambles a victim's files and demands payment.
  • The intrusions were first reported by The Hacker News, drawing on Arctic Wolf's investigation notes.

A firewall is meant to be the front door of a company's network. It decides who gets in and who does not.

So when the front door itself has a broken lock, the consequences are serious. That is what happened here.

Security researchers at Arctic Wolf Labs say they investigated several break-ins during June 2026 that all began the same way. The attackers walked in through a flaw in Palo Alto Networks' PAN-OS, the software that runs the company's widely used firewalls.

The flaw has a formal name: CVE-2026-0257. In plain terms, it is an authentication bypass, meaning an attacker could reach parts of the firewall that are supposed to require a valid login, without having one. It affects the portal and the gateway, the two components staff and remote workers use to connect in.

Palo Alto Networks rated the flaw 7.8 out of 10 on the standard severity scale. That puts it in the high range, though not the very top.

The vendor has since issued a patch. Organisations that have applied it are no longer exposed to this particular bug.

What did the attackers do once they were inside?

They deployed Qilin ransomware, sometimes called Agenda, which is malicious software that encrypts a company's files and demands a payment to unscramble them.

Qilin is a ransomware-as-a-service operation. That means the core group builds the malware and rents it out to other criminals, who carry out the actual break-ins and split the profits. The model has made Qilin one of the more active ransomware brands over the past two years, hitting hospitals, manufacturers and law firms.

Arctic Wolf's account, according to reporting by The Hacker News, describes a familiar pattern. Break in through an internet-facing device. Move quietly across the network. Steal files worth using as leverage. Then trigger the encryption.

What should companies do now?

The short answer is patch, and check the logs.

Any organisation running PAN-OS should confirm it has installed the fix for CVE-2026-0257. Palo Alto Networks publishes its advisories on its security portal at security.paloaltonetworks.com, and the CVE record itself sits on the U.S. government's National Vulnerability Database.

Patching alone is not enough if attackers already slipped in before the fix went on. Security teams should review firewall logs from the spring and early summer of 2026 for unusual logins to the portal or gateway, and for any accounts created or changed without a matching ticket.

For ordinary customers and employees of affected companies, there is nothing to install. But if you receive a notice that your employer or a service you use has suffered a ransomware incident, take it seriously. Change any password you reused elsewhere. Watch bank and email accounts for odd activity over the following months.

Ransomware crews do not always announce themselves right away. Sometimes the quiet weeks after a break-in are when the real damage is arranged.

© 2026 Threat Vectr