VPN appliances remain ransomware crews’ preferred way into a network, and a new authentication-bypass flaw in Palo Alto Networks’ GlobalProtect shows the pattern holding through 2026. CVE-2026-0257, an authentication bypass in the GlobalProtect portal and gateway that lets an attacker without valid credentials establish an authorized-looking VPN session, was added to CISA’s Known Exploited Vulnerabilities catalog on May 29, 2026 after Palo Alto’s own Unit 42 confirmed active exploitation attempts. Arctic Wolf Labs has since tied a series of June 2026 intrusions directly to this vulnerability as the initial access point, with several of them ending in Qilin ransomware deployment.
Why it matters: once inside through the bypassed VPN session, Arctic Wolf observed the intruders move quickly to domain credential extraction and administrative-share lateral movement, then in some cases clear Windows event logs before deploying ransomware, a sequence built specifically to outrun detection and destroy the evidence a SOC would need to reconstruct the intrusion. Arctic Wolf assesses with moderate confidence that exploitation of this flaw leading to Qilin deployment is ongoing, consistent with how ransomware-as-a-service affiliates tend to redistribute a working exploit once one affiliate proves it out.
The original insight for security leaders is less about this specific CVE and more about what it confirms: as this publication noted when SonicWall’s SMA1000 line landed on the same CISA exploited-vulnerabilities list earlier this year, remote-access appliances, not endpoints or email, remain the entry point ransomware affiliates gravitate toward, and GlobalProtect is now part of that same pattern. Because event-log clearing is part of the observed attack chain, organizations should prioritize forwarding GlobalProtect and Windows logs to a centralized SIEM in real time rather than relying on local retention. Patching to the fixed PAN-OS builds, disabling authentication override cookies where they are not strictly needed, and rotating domain credentials after any suspected exposure window are the concrete steps Palo Alto and Arctic Wolf both recommend.