On July 20, 2026, Arctic Wolf Labs published an analysis of multiple intrusions from June that culminated in Qilin ransomware deployment, all originating from the exploitation of CVE-2026-0257, an authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect. The patch had been available since May 13. Rapid7 had already observed widespread exploitation against numerous customers starting May 17. The window between the fix and the first measured attack: four days.
- Arctic Wolf investigated distinct intrusions in June 2026 involving CVE-2026-0257 exploitation leading to Qilin ransomware deployment
- Rapid7 detected exploitation against multiple customers as early as May 17, 2026, four days after Palo Alto Networks released the patch
- CISA added CVE-2026-0257 to the KEV catalog on May 29, 2026, and on July 20 confirmed its exploitation in ransomware campaigns
- Post-exploitation tradecraft varies from rapid encryption-only to full double-extortion, suggesting multiple affiliates operating under the Qilin RaaS model
The Mechanism: From Unauthorized VPN Access to Active Directory Compromise
CVE-2026-0257 resides in the PAN-OS GlobalProtect portal and gateway. According to BleepingComputer citing Palo Alto Networks, the vulnerability "allows the attacker to bypass security restrictions and establish an unauthorized VPN connection." No valid credentials are required to gain initial access.
From that foothold, operators executed a chain of actions documented by National CIO Review with specific technical details: LSASS dumping, extraction of the Active Directory database (NTDS.dit), credential theft, lateral movement via PsExec, RDP, and administrative shares. Investigators also observed the disabling of Microsoft Defender, targeting of Veeam backup solutions, and staging of the ransomware payload in the C:\PerfLogs\ directory.
The path is standard for a full enterprise compromise, but the speed of execution and diversification of post-exploitation tactics distinguish this campaign.
The Time Metric: 4 Days, 46 Days, and the Detection Gap
The measurable timeline offers three anchor points. T-zero: May 13, 2026, Palo Alto Networks patch. T+4: May 17, exploitation observed by Rapid7 against multiple customers. T+46: July 20, Arctic Wolf publicly links the June intrusions to Qilin. On May 29, CISA had already added the vulnerability to the KEV catalog, ordering federal agencies to patch within three days.
Forty-six days between generic exploitation and attribution to a specific ransomware group. The delay is analytical, not technical: Arctic Wolf notes the intrusions showed "tradecraft varied across intrusions, from rapid encryption-only operations to full double-extortion, possibly suggesting multiple affiliates operating under the Qilin ransomware-as-a-service (RaaS) umbrella." The variability makes correlation across seemingly isolated events more difficult.
The RaaS model allows Qilin to distribute the exploit to affiliates with differentiated post-exploitation skills. Some operate with rapid encryption and exit; others build full extortion infrastructures. Unified detection requires reconstructing patterns not from malware behavior, but from the common entry chain: CVE-2026-0257 on GlobalProtect.
Measured Exposure: Over 167,000 Instances Tracked
Shadowserver tracks over 167,000 GlobalProtect instances exposed on the internet. Shodan reports over 172,000 IPs with GlobalProtect fingerprints. According to BleepingComputer, these numbers do not indicate how many instances are vulnerable, how many are patched, or how many are honeypots. The uncertainty is inherent: an exposed instance with an unidentified version can be either a target or an already remediated system.
Palo Alto Networks' installed base exceeds 70,000 global customers, including most major U.S. banks and 90% of the Fortune 10. Geographic and sectoral exposure amplifies the potential impact of the vulnerability.
Qilin, formerly known as Agenda, has been active since August 2022 and has claimed over 2,000 victims on its dark web leak site.
"Arctic Wolf investigated multiple distinct intrusions during June 2026 that resulted in Qilin ransomware deployment, all originating from exploitation of CVE-2026-0257 against Palo Alto Networks firewall appliances" — Arctic Wolf Labs, reported by BleepingComputer
CISA Confirmation and Exploitation Status
On July 20, 2026, CISA updated its entry for CVE-2026-0257 in the KEV catalog, changing the status to "Known To Be Used in Ransomware Campaigns: Known." The confirmation came hours after the Arctic Wolf report publication.
Arctic Wolf assesses with "moderate confidence" that intrusions are ongoing, based on extensive scanning activity detected on the attack surface. The confidence is calibrated: there is no confirmation of real-time exploitation, but scanning patterns indicate sustained activity against vulnerable systems.
The absence of a structured ZDI or GHSL advisory in the dossier leaves the exact technical details of the bypass mechanism undocumented. NVD lists CPEs for PAN-OS versions 10.2.x, 11.1.x, and 11.2.x, but does not indicate specific versions with the fix applied.
Immediate Actions
For organizations using Palo Alto Networks GlobalProtect:
- Verify the patch status of exposed PAN-OS systems, prioritizing internet-accessible GlobalProtect gateways
- Search network telemetry for anomalous authenticated VPN connections or access patterns from addresses not attributable to the legitimate user base, consistent with the documented bypass vector
- Inspect logs for lateral movement activity via PsExec, RDP, and administrative share access, particularly near GlobalProtect systems
- Check the integrity of Veeam backup solutions and the status of Microsoft Defender security logs, both documented targets in the countermeasure-disabling phase
The RaaS Problem as an Exploit Distribution System
The Qilin campaign on CVE-2026-0257 is not a centralized operation but a distributed economy. The exploit functions as a standardized entry point; affiliates add post-exploitation according to their skills and preferences. Some encrypt quickly; others build leak infrastructures. The variety is a competitive advantage for the group: it makes detection signatures harder to craft and lengthens analytical correlation time.
The data that emerges clearly is temporal compression. Four days between patch and exploitation are insufficient for most organizations with structured change management processes. Forty-six days between exploitation and ransomware attribution indicate that the intelligence gap remains significant even for sophisticated vendors. The metric that matters is not just patch time, but risk comprehension time.
Sources
- https://www.bleepingcomputer.com/news/security/critical-globalprotect-vpn-bug-now-exploited-in-ransomware-attacks/
- https://nationalcioreview.com/articles-insights/extra-bytes/critical-palo-alto-vpn-vulnerability-now-linked-to-qilin-ransomware-attacks/
- https://www.news4hackers.com/urgent-critical-palo-alto-vpn-vulnerability-exploited-by-qilin-ransomware-gang
- https://thecyberwire.com/newsletters/daily-briefing/15/137
- https://www.secnews.gr/en/722805/qilin-ransomware-exploit-bug-globalprotect/
- https://nvd.nist.gov/vuln/detail/CVE-2026-0257
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search=CVE-2026-0257&field_date_added_wrapper=all&field_cve=&sort_by=field_date_added&items_per_page=20&url=
- https://www.bleepingcomputer.com/
- https://www.bleepingcomputer.com/tutorials/
- https://www.bleepingcomputer.com/download/
Information verified against cited sources and current as of publication.