Skip to content

Qilin Ransomware Exploits PAN-OS Authentication Flaw as Initial Access Vector

In short: Qilin ransomware attackers exploit CVE-2026-0257 (CVSS 7.8), an authentication bypass in PAN-OS, as their initial access vector.

Threat actors have successfully exploited CVE-2026-0257, an authentication vulnerability in Palo Alto Networks PAN-OS, to gain initial compromise of systems and subsequently deploy Qilin ransomware (also known as Agenda). Arctic Wolf Labs documented multiple attacks in June 2026 based on this vulnerability.

The vulnerability CVE-2026-0257 affects the Portal and Gateway components of Palo Alto Networks PAN-OS with a CVSS score of 7.8 and had already been patched at the time of investigation. It allows unauthenticated attackers to bypass authentication mechanisms and gain access to affected systems.

Arctic Wolf Labs observed an attack campaign in June 2026 in which Qilin actors deliberately exploited this flaw as an entry point. Following initial compromise via authentication bypass, further steps were taken to deploy ransomware to target environments. This follows the typical attack flow: initial unauthenticated access through a known vulnerability, persistence establishment, and subsequent payload distribution.

CISOs should ensure that all Palo Alto Networks PAN-OS instances are patched with the available fix for CVE-2026-0257. This is particularly critical for systems that are externally exposed or function as gateways. In parallel, detection measures should be strengthened for anomalous authentication attempts and unauthorized Portal/Gateway access. Network monitoring should watch for signs of suspicious lateral movement activities, especially following successful authentication without corresponding user action.


Source: thehackernews.com · Published 21 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: