Arctic Wolf ties CVE-2026-0257 GlobalProtect bypass to Qilin ransomware
Arctic Wolf documented Qilin ransomware deployments through Palo Alto CVE-2026-0257 in June — six weeks after Rapid7 first flagged the auth-bypass exploitation and CISA added the CVE to KEV.
Arctic Wolf published Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware on July 21, tying June 2026 intrusions of Palo Alto Networks PAN-OS GlobalProtect portals to full-domain Qilin ransomware deployments. The initial access vector is CVE-2026-0257 — the CVSS 7.8 authentication-override cookie bypass Palo Alto patched on May 13 and CISA added to KEV on May 29. Arctic Wolf assessed with moderate confidence that "intrusions leveraging CVE-2026-0257 and leading to Qilin ransomware deployment are likely ongoing."
What Arctic Wolf saw
- Initial access: attackers with the authentication-override cookie set alongside a shared certificate configuration forge a valid GlobalProtect session, bypassing perimeter authentication entirely.
- Access mode: the forged session is a legitimate VPN tunnel from the network's point of view — no exploit shellcode, no unusual protocol traffic on the wire, just a valid user profile appearing on the corporate LAN.
- Post-access TTPs: LSASS dumping and NTDS extraction from domain controllers, credential-driven lateral movement over Windows administrative shares (
ADMIN$,C$), abuse of compromised admin accounts to run remote commands on the fleet. - Payload: the Qilin ransomware-as-a-service brand encrypts domain-joined hosts at scale after credential compromise.
- Observation window: June 2026 (per Arctic Wolf's report), six weeks after the initial May 13 patch.
Arctic Wolf's companion advisory notes an increase in CVE-2026-0257 exploitation attempts against its own customer base leading into that window.
What the bug is
Recap from Palo Alto's May 13 advisory (context in our initial coverage):
- CVE-2026-0257 — authentication bypass in PAN-OS GlobalProtect portal and gateway.
- CVSS 3.1 base: 7.8.
- Trigger: authentication-override cookies enabled alongside a specific shared-certificate configuration lets an unauthenticated attacker forge a valid session cookie and complete VPN login without credentials.
- Affected releases: PAN-OS 12.1, 11.2, 11.1, and 10.2 prior to the May 13 patched builds, plus specific Prisma Access releases.
- CISA KEV added: May 29, 2026 (federal patch deadline June 19).
Exploitation status
Confirmed and escalating. Rapid7 observed the first in-the-wild exploitation on May 17, 2026 — four days after the patch shipped. Arctic Wolf's June intrusion set now tags the same CVE as the initial access for at least one active RaaS brand deploying ransomware at scale. Bleeping Computer surfaced the tie-in this morning; the primary source is Arctic Wolf's own writeup.
Action checklist
- Confirm every GlobalProtect portal is on a patched PAN-OS build. The May 13 releases close the bug on PAN-OS 12.1, 11.2, 11.1, and 10.2. Prisma Access customers should confirm their tenant is on the corresponding patched build.
- Disable authentication-override cookies unless you actively use them. The bug is only exploitable when this feature is enabled alongside the vulnerable certificate configuration. If your deployment does not rely on override cookies for SSO handoff, turn them off.
- Assume credential exposure on any unpatched portal that saw internet traffic between May 13 and today. Arctic Wolf's post-access TTP set is LSASS dumping and NTDS extraction — every domain credential in scope of a compromised session should be rotated, including service accounts.
- Hunt for the specific Qilin TTPs Arctic Wolf documents. Their writeup includes the LSASS/NTDS behaviour and administrative-share lateral movement; if you have EDR telemetry going back to June, sweep for those patterns on any host reachable from a compromised VPN session.
- KEV deadline has passed for federal operators. Any FCEB agency that has not remediated is already non-compliant with BOD 22-01. Escalate accordingly.
Context
The pattern here is the one CISA warned about when the CVE was added to KEV: edge VPN authentication bypasses transition from exploit chatter to ransomware payload in weeks, not months. Rapid7 flagged CVE-2026-0257 on May 17; the CISA KEV entry landed May 29; Arctic Wolf now dates full Qilin deployments to June. That is a five-week window from patch release to encrypted domain — comparable to recent Cisco ASA and Fortinet FortiGate deployment cycles.
Qilin remains one of the most active RaaS brands of the year, with confirmed operations across manufacturing, healthcare, and legal. Arctic Wolf's attribution — moderate confidence — is appropriately hedged: TTP overlap and initial access alignment are enough to name the payload but not to name the affiliate. Whoever the affiliate is, the initial access is a public CVE with a two-month-old patch. That is a self-inflicted wound at this point in the cycle.