Threat actors are actively exploiting CVE-2026-0257, an authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect, to gain remote access and deploy Qilin ransomware. The attacks target internet-facing firewalls and Prisma Access deployments, allowing attackers to establish VPN sessions that appear legitimate. Read the Cybersecurity Threat Advisory now to mitigate you and your clients’ risk now.
What is the threat?
CVE-2026-0257 affects GlobalProtect portals and gateways under certain configurations. The flaw can allow an attacker to establish a VPN session without valid credentials, making the connection appear legitimate.
The vulnerability affects PAN-OS 12.1, 11.2, 11.1, and 10.2 versions released before Palo Alto’s fixes, along with certain Prisma Access deployments.
After gaining access, Qilin operators establish persistence, deploy remote access tools such as AnyDesk, Ngrok, and LogMeIn, harvest credentials, and extract Active Directory data. They then move laterally through the environment and deploy ransomware after disabling security controls and clearing logs.
Why is it noteworthy?
This vulnerability allows attackers to gain trusted VPN access without credentials, bypassing controls that typically rely on user authentication and MFA.
Researchers have linked the activity to the Qilin ransomware-as-a-service (RaaS) operation. As a result, multiple threat actors may adopt the exploit. Once inside, attackers can steal credentials, exfiltrate data, move laterally, and deploy ransomware. This creates significant risk for organizations with exposed GlobalProtect environments.
What is the exposure or risk?
Organizations running vulnerable PAN-OS or Prisma Access systems with internet-facing GlobalProtect services are at high risk.
Successful exploitation gives attackers access to internal systems, including servers, administrative interfaces, and domain controllers. They may steal credentials, extract Active Directory data, install persistence mechanisms, exfiltrate sensitive information, and ultimately deploy ransomware across the environment.
Attackers also use cloud storage services to hold stolen data. They often disable Microsoft Defender and clear event logs to hinder detection and investigation. Even after patching, organizations remain at risk if they do not terminate active VPN sessions or reset compromised credentials.
What are the recommendations?
Barracuda recommends the following actions to mitigate risk:
- Patch all affected PAN-OS and Prisma Access systems immediately.
- Terminate all active GlobalProtect VPN sessions after patching.
- Review GlobalProtect configurations, including authentication override cookies and certificate settings, and align them with Palo Alto best practices.
- Reset privileged and domain credentials if compromise is suspected and enforce MFA for VPN and administrative access.
- Monitor for suspicious activity involving tools such as PsExec, AnyDesk, Ngrok, LogMeIn, Rclone, rundll32.exe, comsvcs.dll, and ntdsutil.exe.
- Send logs to a centralized SIEM or logging platform to preserve visibility if local logs are deleted.
- Restrict VPN access and apply least-privilege access controls to sensitive systems.
References
For more in-depth information about the recommendations, please visit the following link:
If you have any questions about this Cybersecurity Threat Advisory, don’t hesitate to get in touch with Barracuda Managed XDR’s Security Operations Center.

