CVE Tools

Critical Palo Alto VPN bug now exploited by Qilin ransomware gang

BleepingComputerBy Sergiu Gatlan

Reported exploitedGlobalProtectQilin

Our summary

The Qilin ransomware group is actively exploiting a critical authentication bypass vulnerability in Palo Alto Networks' GlobalProtect VPN software (CVE-2026-0257) to gain unauthorized access and deploy ransomware. The flaw was patched on May 13, but attackers began using it as early as May 17, with CISA adding it to its Known Exploited Vulnerabilities list on May 29. Cybersecurity firm Arctic Wolf confirmed multiple breaches linked to this exploit, resulting in widespread encryption of victim systems. With over 170,000 exposed GlobalProtect instances tracked online, urgent remediation is advised for any unpatched deployments.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store