Exploited in the wild PAN-OS Qilin Ransomware Group ransomware Palo Alto Networks network-edge
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
CVE Tools coverage
Threat actors are actively exploiting a recently patched vulnerability in Palo Alto Networks' PAN-OS software to gain unauthorized access and deploy the Qilin ransomware. The flaw, CVE-2026-0257, allows attackers to bypass authentication and establish SSL VPN sessions when certain certificate configurations are enabled. Arctic Wolf Labs reported multiple incidents in June 2026 where this vulnerability was leveraged as an initial access vector, leading to varied post-exploitation tactics including encryption and data exfiltration. Affected systems should apply available patches immediately.