Palo Alto PAN-OS Vulnerability Exploited for Qilin Ransomware

Qilin ransomware deployed via PAN-OS GlobalProtect auth bypass

Hackers are actively exploiting a critical Palo Alto PAN-OS vulnerability, known as CVE-2026-0257, to bypass authentication and deploy Qilin ransomware on corporate networks. This flaw, which affects the GlobalProtect portal and gateway, has been linked to several intrusions throughout June 2026, raising urgent concerns for organisations using impacted PAN-OS versions.

How Attackers Exploit the PAN-OS GlobalProtect Vulnerability

The vulnerability, tracked as CVE-2026-0257 and carrying a CVSS score of 7.8, resides in the GlobalProtect portal and gateway within Palo Alto Networks PAN-OS. It becomes exploitable when authentication override cookies are enabled in conjunction with specific certificate configurations. This combination allows unauthenticated attackers to entirely bypass login controls and establish VPN sessions that appear legitimate.

Affected products and versions include:

  • PAN-OS 12.1, 11.2, 11.1, and 10.2 (prior to patched builds)
  • Certain versions of Prisma Access

Palo Alto Networks has confirmed that active exploitation is occurring in the wild, with multiple breaches reported and investigated by security firm Arctic Wolf Labs in June 2026. In each case, attackers used the vulnerability as the initial access vector, bypassing perimeter authentication controls and gaining direct access to internal networks.

Detailed Attack Timeline and Techniques

Once attackers established VPN sessions using the vulnerability, they executed a series of post-exploitation techniques designed for persistence, reconnaissance, lateral movement, and data exfiltration. The observed sequence of attacker behaviour includes:

  • Persistence: Attackers created registry Run keys with a unique naming pattern (an asterisk followed by six random lowercase letters) to maintain access across reboots.
  • Remote Access Tools: Tools such as AnyDesk, Ngrok, and LogMeIn were deployed for redundant connectivity, ensuring continued access even if initial sessions were disrupted.
  • Credential Dumping: Credentials were extracted from LSASS memory using rundll32.exe and comsvcs.dll. The output was disguised as a .odt file, helping evade detection by security tools.
  • Active Directory Database Extraction: Attackers used ntdsutil.exe to exfiltrate the entire Active Directory database, providing domain-wide credential access.
  • Lateral Movement: Tools like PsExec and administrative shares (C$) enabled attackers to move across the network and escalate their impact.

Several attacks were traced back to systems identifying themselves with the hostname “kali,” and overlapping IP addresses were used throughout both initial and subsequent VPN sessions. This suggests the use of shared infrastructure or tooling among Qilin ransomware affiliates, consistent with ransomware-as-a-service (RaaS) operations.

After gaining access, attackers adapted their techniques depending on the target. Some intrusions proceeded rapidly to file encryption, while others involved extensive reconnaissance and large-scale credential harvesting. In cases where data exfiltration was observed, Rclone was used to transfer stolen data to MEGA cloud storage prior to ransomware deployment.

Attackers routinely disabled Microsoft Defender’s real-time protection before encryption and wiped Windows Event Logs using a PowerShell script that cleared all log channels. This made forensic analysis and recovery efforts significantly more difficult for incident responders.

The ransomware payload itself was consistently named win.exe and was staged in the C:\PerfLogs\ directory, a default Windows location that is rarely monitored. The executable required a password parameter for execution, complicating analysis by security sandboxes.

Scope, Impact, and Current Exploitation Status

The campaign targeting CVE-2026-0257 has affected organisations running unpatched versions of PAN-OS 12.1, 11.2, 11.1, and 10.2, as well as certain Prisma Access deployments. While Palo Alto Networks has issued security advisories and released patches, exploitation remains limited but ongoing in the wild. The observed attacks indicate that threat actors are acting quickly to take advantage of unpatched systems, with some incidents progressing from initial access to ransomware deployment in a matter of hours.

Qilin ransomware affiliates demonstrate varying levels of sophistication, with some opting for immediate encryption and others conducting extensive reconnaissance and data exfiltration. The use of shared infrastructure and tooling, along with the adaptability of post-exploitation tactics, highlights the evolving nature of ransomware threats targeting perimeter devices.

Why This Palo Alto Vulnerability Matters

This vulnerability is critical because it allows attackers to completely bypass authentication on internet-facing firewalls, granting them direct access to internal networks. The rapid exploitation and the deployment of sophisticated ransomware operations such as Qilin underline the need for immediate response from affected organisations. The breach of credential stores and exfiltration of sensitive data amplify the potential impact of these attacks.

Actionable Recommendations for Organisations

  • Immediately apply patches for CVE-2026-0257 to all affected PAN-OS and Prisma Access systems.
  • Terminate all active GlobalProtect sessions after patching to remove compromised connections.
  • Rotate all domain credentials, including the KRBTGT account, if exploitation is suspected.
  • Monitor and restrict execution from the C:\PerfLogs\ directory, as this is used for staging ransomware payloads.
  • Review logs and look for indicators of compromise, including the use of remote access tools and suspicious registry Run key patterns.

Taking swift action to patch affected systems, revoke potentially compromised credentials and monitor for signs of intrusion is essential to limiting the impact of this threat.

Originally reported by cybersecuritynews.com.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call