Executive Summary

    On July 20th, 2026 it was reported by security researchers that Qilin Ransomware affiliates are actively exploiting CVE-2026-0257, a critical authentication bypass vulnerability affecting Palo Alto Networks Global Protect Portal.

    The vulnerability was previously added to CISA’s Known Exploited Vulnerabilities (KEV) database on May 29th. Tracked as CVE-2026-0257, the flaw can allow an unauthenticated attacker to establish unauthorized VPN sessions on vulnerable GlobalProtect deployments when certain configuration conditions are present.

    The vulnerability was originally released by Palo Alto May 13th, 2026 as a medium severity vulnerability. However, given confirmed exploitation in the wild and weaponization by well-established ransomware operators, Beazley Security strongly recommends affected organizations patch immediately.

    Affected Systems or Products

    Product

    Affected Version

    Fixed Version

    PAN-OS 12.1

    12.1.5 through 12.1.6 12.1.2 through 12.1.4-h*

    ≥12.1.7 ≥12.1.4-h6 or ≥12.1.7

    PAN-OS 11.2

    11.2.11 or later 11.2.8 through 11.2.10-h* 11.2.5 through 11.2.7-h* 11.2.0 through 11.2.4-h*

    ≥11.2.12 ≥11.2.10-h7 or ≥11.2.12 ≥11.2.7-h14 or ≥11.2.12 ≥11.2.4-h17 or ≥11.2.12

    PAN-OS 11.1

    11.1.14 or later 11.1.11 through 11.1.13-h* 11.1.8 through 11.1.10-h* 11.1.7 through 11.1.7-h* 11.1.5 through 11.1.6-h* 11.1.0 through 11.1.4-h*

    ≥11.1.15 ≥11.1.13-h5 or ≥11.1.15 ≥11.1.10-h25 or ≥11.1.15 ≥11.1.7-h6 or ≥11.1.15 ≥11.1.6-h32 or ≥11.1.15 ≥11.1.4-h33 or ≥11.1.15

    PAN-OS 10.2

    10.2.17 through 10.2.18-h* 10.2.14 through 10.2.16-h* 10.2.11 through 10.2.13-h* 10.2.8 through 10.2.10-h* 10.2.0 through 10.2.7-h*

    ≥10.2.18 or ≥10.2.18-h6 ≥10.2.16-h7 or ≥10.2.18-h6 ≥10.2.13-h21 or ≥10.2.18-h6 ≥10.2.10-h36 or ≥10.2.18-h6 ≥10.2.7-h34 or ≥10.2.18-h6

    Prisma Access 10.2

    10.2.0 through 10.2.10-h*

    ≥10.2.10-h36

    Prisma Access 11.2

    11.2.0 through 11.2.7-h*

    ≥11.2.7-h13

    Mitigations / Workarounds

    As active exploitation has been confirmed in the wild and Palo Alto have released fixes for this vulnerability, and affected organizations should apply patches as soon as possible. Ifimmediately updating is not an option, risk can be temporarily reduced by the following mitigation steps:

    • Disable Authentication Override within the GlobalProtect portal. Configuration steps are included within Palo Alto’s original advisory.

    • Restricting access to GlobalProtect to trusted networks where operationally feasible until patches can be applied.

    • If Authentication Override is required, use a dedicated certificate exclusively for signing Authentication Override cookies and ensure keys are securely stored and managed.

    Additionally, CISA recommends either turning off the vulnerable technologies or restricting the VPN access to them only to trusted IP addresses. It is suggested to monitor VPN connection logs for suspicious authentication patterns and to consider implementing additional authentication methods outside of GlobalProtect.

    Indicators of Compromise

    On July 20th, Arctic Wolf reported multiple engagements in which Qilin ransomware affiliates exploited CVE-2026-0257 as the initial access vector. Following successful exploitation, the threat actors established GlobalProtect SSL VPN sessions from systems identifying themselves with the hostname “kali”. In the investigated intrusions, VPN sessions originated from the following IP addresses:

    • 108.61.229[.]217

    • 108.61.75[.]232

    • 2.188.33[.]52

    • 199.247.22[.]193

    • 70.34.205[.]43

    Arctic Wolf has made available and are updating this GitHub repository with additional IoCs related to the campaign.

    Technical Details

    Palo Alto suggests that the vulnerability came from an authentication bypass vulnerability in GlobalProtect which allows attackers to bypass security restrictions and establishunauthorized VPN connections. This vulnerability is being actively exploited in the wild by ransomware operaters, as reported by security researchers at Arctic Wolf.

    To be exploited, specific conditions on the GlobalProtect portal must be met. First, the authentication override feature must be enabled. Then, an affected device would need to be configured in a way where the certificate used for the authentication override cookie mechanism is also used elsewhere, like the GlobalProtect portal or the gateway HTTPS service. If this is the case, threat actors may be able to derive the public key, enabling the crafting of malicious override cookies. A possible attack chain would resemble as follows:

    • The attacker retrieves a public encryption certificate from the target’s GlobalProtect portal or gateway to forge an authentication override cookie

    • The attacker uses the certificate to encrypt an arbitrary authentication bypass cookie

    • The maliciously crafted bypass cookie is implicitly trusted by the device, allowing access

    To check a device configuration, users can look under Network > GlobalProtect > Gateways > [Gateway/Portal Name] > Agent Tab > Authentication Override Cookie to see if the functionality is enabled.

    Due to active exploitation in the wild, publicly available proof of concept exploit code, and potential for unauthorized access through the VPN gateway, Beazley Security stronglyrecommends affected organizations patch immediately.

    How Beazley Security is responding

    Beazley Security is monitoring client perimeter devices through our Exposure Management Platform to identify impacted devices and support organizations in remediation of any issues found.

    We are also conducting threat hunts across our MDR environment to detect potential exploitation attempts against our clients.

    If you believe your organization may have been impacted by this attack campaign and need support, please contact our Incident Response team.