Critical

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

The Hacker News
Actively Exploited

Overview

Cybercriminals are exploiting a serious vulnerability in Palo Alto Networks' PAN-OS to gain access and deploy Qilin ransomware, also known as Agenda. This vulnerability, identified as CVE-2026-0257, has a CVSS score of 7.8 and allows attackers to bypass authentication on both the portal and gateway. Arctic Wolf Labs reported multiple incidents in June 2026 where this flaw was used to infiltrate systems. Although the vulnerability has been patched, organizations need to ensure their systems are updated to prevent potential attacks. The Qilin ransomware can lead to significant data loss and operational disruption, emphasizing the need for vigilance in cybersecurity practices.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Palo Alto Networks PAN-OS, specifically the portal and gateway systems affected by CVE-2026-0257.
  • Action Required: Organizations should apply the latest patches released by Palo Alto Networks for PAN-OS to close the authentication bypass vulnerability.
  • Timeline: Disclosed on June 2026

Original Article Summary

Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway

Impact

Palo Alto Networks PAN-OS, specifically the portal and gateway systems affected by CVE-2026-0257.

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Disclosed on June 2026

Remediation

Organizations should apply the latest patches released by Palo Alto Networks for PAN-OS to close the authentication bypass vulnerability. Regularly updating systems and configuring security settings to limit access can help mitigate risks.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Ransomware, CVE, Exploit, and 2 more.

Related Coverage

Palo Alto Networks launches AI safety toolkit for schools

SCM feed for Latest

Palo Alto Networks has launched a free digital literacy toolkit in collaboration with Cyberlite to help educators teach students about AI-driven threats. This initiative aims to combat the rising use of artificial intelligence by cybercriminals, emphasizing the importance of digital literacy in recognizing and resisting such threats.

Dec 3, 2025

WormGPT 4 and KawaiiGPT: New Dark LLMs Boost Cybercrime Automation

SecurityWeek

Palo Alto Networks has identified new malicious language models, WormGPT 4 and KawaiiGPT, that are being utilized by cybercriminals to enhance their phishing, malware development, and reconnaissance efforts. The rise of these dark LLMs represents a significant threat to cybersecurity, automating and streamlining various cybercrime activities.

Nov 25, 2025

​​Spyware Allows Cyber Threat Actors to Target Users of Messaging Applications​

All CISA Advisories

CISA has identified that various cyber threat actors are using commercial spyware to target users of mobile messaging applications, employing tactics such as phishing, zero-click exploits, and impersonation. The focus is primarily on high-value individuals including government and military officials, indicating a serious threat to sensitive communications.

Nov 24, 2025

In Other News: ATM Jackpotting, WhatsApp-NSO Lawsuit Continues, CISA Hiring

SecurityWeek

The article highlights several significant cybersecurity incidents, including a data breach affecting 120,000 individuals and a surge in scanning activities by Palo Alto Networks. Additionally, it mentions ongoing legal battles involving WhatsApp and NSO, as well as the emergence of AI-related security threats such as second-order prompt injection attacks.

Nov 21, 2025

Attackers launch dual campaign on GlobalProtect portals and SonicWall APIs

Security Affairs

A hacking campaign has been targeting GlobalProtect logins and scanning SonicWall APIs since December 2, 2025. The attack is significant due to its scale, involving over 7,000 IP addresses linked to a German hosting provider, indicating a coordinated effort that poses a serious threat to the security of affected systems.

Dec 6, 2025

React2Shell Vulnerability Actively Exploited to Deploy Linux Backdoors

The Hacker News

The React2Shell vulnerability is currently being exploited by cybercriminals to install malware on Linux systems. Researchers from Palo Alto Networks and NTT Security have identified that this vulnerability facilitates the deployment of malicious tools like KSwapDoor and ZnDoor. KSwapDoor is particularly concerning as it is a sophisticated remote access tool designed to operate stealthily, allowing attackers to maintain control over compromised systems without detection. This ongoing threat affects organizations running vulnerable Linux environments, making it crucial for them to take immediate action to secure their systems. Users need to be aware of the risks and ensure their defenses are updated to mitigate potential attacks.

Dec 16, 2025