Qilin Ransomware Gang Is Actively Exploiting Palo Alto's GlobalProtect VPN
Palo Alto Networks' GlobalProtect VPN software — a product used by over 70,000 organisations worldwide, including 90% of Fortune 10 companies — has a critical authentication bypass flaw that the Qilin ransomware gang is now weaponising at scale, according to Arctic Wolf.
The flaw, CVE-2026-0257, lets an attacker skip the login process entirely and connect to a corporate VPN as if they belong there. Once inside, Qilin affiliates have been deploying full ransomware encryption across entire corporate networks, with some victims facing double-extortion (where attackers both encrypt files and threaten to publish stolen data publicly).
Arctic Wolf investigated multiple separate incidents during June 2026, all tracing back to this same vulnerability. The activity is assessed as ongoing.
Internet threat watchdog Shadowserver tracks over 167,000 GlobalProtect instances currently exposed to the public internet. There is no confirmed figure for how many remain unpatched.
Qilin is a ransomware-as-a-service (RaaS) operation — meaning the group behind it rents their attack tools to other criminals, who then run their own campaigns and share the proceeds. Past victims include Nissan, pathology provider Synnovis, and Australia's Court Services Victoria.
CISA added CVE-2026-0257 to its Known Exploited Vulnerabilities catalog on May 29, ordering federal agencies to patch within three days.
What you should do: If your organisation uses Palo Alto Networks GlobalProtect, confirm with your IT team that the May 13 patch has been applied. If you are unsure, assume it has not been and escalate today.
Sources

