CVE Tools
Back to feed
Exploited in the wild PAN-OS Qilin Ransomware Group ransomware Palo Alto Networks network-edge

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

The Hacker News·By The Hacker News··2 min read
CVE Tools coverage

Threat actors are actively exploiting a recently patched vulnerability in Palo Alto Networks' PAN-OS software to gain unauthorized access and deploy the Qilin ransomware. The flaw, CVE-2026-0257, allows attackers to bypass authentication and establish SSL VPN sessions when certain certificate configurations are enabled. Arctic Wolf Labs reported multiple incidents in June 2026 where this vulnerability was leveraged as an initial access vector, leading to varied post-exploitation tactics including encryption and data exfiltration. Affected systems should apply available patches immediately.