Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
By Dillip Chowdary • Jul 21, 2026 • Source: BleepingComputer
The Qilin ransomware gang is actively exploiting a critical authentication bypass in Palo Alto Networks PAN-OS GlobalProtect VPN to break into victim networks, according to cybersecurity firm Arctic Wolf, as reported by BleepingComputer. The flaw sits in the GlobalProtect portal and gateway path that many organizations use as the front door to remote access. Attackers who clear that gate can reach internal systems without valid credentials, turning a perimeter control into an entry point for ransomware.
GlobalProtect is the remote-access component of PAN-OS. It terminates VPN sessions and enforces who may connect before traffic is allowed onto the corporate network. An authentication bypass at that layer means the product can accept or complete access flows without correctly verifying the caller. For operators, that is not a secondary bug in a side feature; it is a failure in the control that is supposed to decide network membership. Once past GlobalProtect, an attacker can move laterally, harvest credentials, and stage ransomware with the same access path employees use day to day.
Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
For engineers and builders who depend on VPN edge devices, this is a direct operational risk. Many designs treat the GlobalProtect boundary as a hard trust boundary: patch it, lock it down, and assume unauthenticated traffic stops there. Active ransomware abuse of an auth bypass invalidates that assumption until the edge is fixed or isolated. Incident response, network segmentation, and identity controls behind the VPN become the real last line of defense when the portal itself can be skipped.
Qilin is a known ransomware operator, and ransomware groups routinely hunt for remote-access and edge flaws because a single compromised VPN often maps to many high-value targets. Palo Alto GlobalProtect is widely deployed in enterprises that already centralize remote work through one vendor stack. That combination—popular perimeter product plus a critical auth bypass—explains why Arctic Wolf is tying Qilin activity to this specific PAN-OS path rather than to random phishing alone. Edge VPN bugs of this class sit in the same threat lane as other high-impact remote-access compromises that ransomware crews have preferred for years.
Watch for confirmed exploitation patterns against GlobalProtect portals, Arctic Wolf and peer telemetry on Qilin campaigns, and any vendor guidance on remediation or compensating controls for the authentication bypass. Until affected GlobalProtect deployments are addressed, treat exposed portals as high-risk surfaces: restrict reachability where possible, monitor for anomalous VPN and post-auth activity, and assume ransomware operators will keep probing this class of flaw as long as it remains useful for network entry.
Advertisement