PAN-OS GlobalProtect flaw now leads to Qilin ransomware intrusions
Arctic Wolf says CVE-2026-0257 has moved from observed GlobalProtect exploitation to Qilin ransomware intrusions, giving PAN-OS administrators a concrete reason to re-check patched versions, cookie settings, VPN logs, and credential exposure.
Arctic Wolf Labs says it investigated multiple June 2026 intrusions where attackers used CVE-2026-0257 against Palo Alto Networks firewall appliances as the initial access path, then moved into Qilin ransomware deployment. That changes the operational priority for teams that treated the flaw as a narrow GlobalProtect configuration issue in May.
CVE-2026-0257 is an authentication bypass in PAN-OS GlobalProtect portal and gateway deployments. Palo Alto Networks says the issue applies when authentication override cookies are enabled with a specific certificate configuration; successful exploitation can let a remote attacker establish an unauthorized VPN connection.
Qilin activity raises the cost of delay
Arctic Wolf's new report describes several distinct victim environments where exploitation of CVE-2026-0257 was followed by credential theft, lateral movement, persistence, and ransomware staging. The report says the post-exploitation tradecraft varied: some cases moved quickly to encryption, while others showed double-extortion behavior with data theft before payload deployment.
The common entry point matters more than the individual ransomware brand. A vulnerable VPN edge device can turn into authenticated internal access, which gives attackers a cleaner path to domain credentials, administrative shares, backup infrastructure, and file servers. Arctic Wolf observed repeated staging under C:\PerfLogs\, PsExec-based lateral execution, LSASS dumping, NTDS extraction, remote access tooling, log clearing, and cloud-storage exfiltration activity in parts of the intrusion set.
The vulnerable GlobalProtect pattern is specific
Palo Alto Networks lists PAN-OS 10.2, 11.1, 11.2, 12.1, and some Prisma Access versions as affected before fixed builds, depending on the exact branch. Panorama and Cloud NGFW are listed as not impacted. The advisory says the risky condition involves GlobalProtect portal or gateway configurations where authentication override cookies are enabled and certificates are used in a way that does not isolate the cookie function.
Rapid7's earlier analysis gives the exploit path useful shape for defenders. Its researchers observed cookie authentication to local administrator accounts across customer environments, then validated that a forged authentication override cookie could be accepted when the deployment reused discoverable certificate material. Palo Alto later raised the advisory severity to High and acknowledged limited exploit attempts against unpatched devices without mitigations.
What administrators should verify now
Start with the vendor advisory, because fixed versions differ by PAN-OS branch. Palo Alto's current guidance includes upgrading affected GlobalProtect portals and gateways, disabling authentication override where possible, or generating a dedicated certificate used only for authentication override cookies. In phased upgrades, the vendor also documents a temporary compatibility setting; that should not become a permanent exception.
Then hunt for evidence of use. Unit 42 recommends searching GlobalProtect logs for successful gateway-connected events tied to suspicious device names, host IDs, and known activity indicators. Rapid7's observed examples included local account logons, spoofed or repeated device traits, hosting-provider source infrastructure, and cookie-based authentication where normal user behavior would not fit.
For environments with a suspected successful connection, broaden the response quickly:
- Rotate privileged credentials, including domain administrator accounts and
KRBTGTwhere domain compromise is plausible. - Check for LSASS dumps, NTDS extraction, PsExec service creation, suspicious RDP, and executables staged under
C:\PerfLogs\. - Review outbound transfers to cloud storage providers from domain controllers, file servers, backup hosts, or systems that do not normally move bulk data.
- Confirm Windows event logs are forwarded centrally, since Arctic Wolf saw broad local log clearing during intrusions.
CISA already treats CVE-2026-0257 as exploited
CISA added CVE-2026-0257 to the Known Exploited Vulnerabilities catalog on May 29, 2026 and marks known ransomware campaign use as "Known" in its machine-readable feed. The federal remediation due date has already passed, but the Arctic Wolf findings give private-sector teams a fresher reason to re-check exposure, especially where GlobalProtect changes were delayed, partially staged, or treated as a normal maintenance item.
The concrete action is simple: confirm fixed PAN-OS versions, remove the vulnerable cookie/certificate pattern, and investigate any successful suspicious GlobalProtect sessions as potential initial access. The unresolved question is how many perimeter devices were patched after credentials had already been harvested.
