🔴 Critical | Source: The Hacker News
Attackers are exploiting CVE-2026-0257, a high-severity authentication bypass flaw in Palo Alto Networks PAN-OS, to gain initial access to victim networks before deploying Qilin ransomware. Arctic Wolf Labs identified multiple intrusions in June 2026 following this pattern. The vulnerability affects PAN-OS portals and gateways, making it a prime target for ransomware groups seeking an unauthenticated foothold.
Security Architect’s Take: If you have internet-facing PAN-OS portals or gateways, verify the patch for CVE-2026-0257 has been applied immediately and review your firewall access logs from June 2026 onwards for signs of unauthorised authentication attempts or lateral movement consistent with Qilin TTPs.
Original advisory: Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access