Overview
- Palo Alto released a patch for CVE-2026-0257 on May 13 and the U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerability catalog on May 29.
- Researchers say the bug lets attackers bypass GlobalProtect login checks to establish SSL VPN sessions without credentials, which they then use to harvest accounts and move laterally across networks.
- Arctic Wolf investigated multiple intrusions in June that began with the GlobalProtect bypass and led to Qilin (Agenda) ransomware, and the firm assesses with moderate confidence that affiliate-driven exploitation is likely ongoing.
- Observed attacker methods include staging ransomware in C:\PerfLogs, using PsExec over Windows admin shares, disabling Microsoft Defender, clearing logs, and sometimes exfiltrating data to cloud services before encryption.
- Internet scans show roughly 167,000–172,000 GlobalProtect fingerprints exposed online, so organizations should apply patches, force VPN re-authentication, check logs for anomalous VPN sessions, enable layered access controls, and assume unpatched appliances may already be compromised.