Ransomware Gangs Exploiting Palo Alto GlobalProtect Bypass to Infiltrate VPN Access

Several ransomware groups are actively abusing a recently disclosed flaw in Palo Alto Networks GlobalProtect (CVE-2026-0257) to stealthily establish VPN sessions without proper credentials. This vulnerability—affecting PAN-OS and Prisma Access—has been identified in operations by Qilin and Settra, which use it to enter internal networks through trusted remote access paths. Unauthorized access via this flaw often goes unnoticed, since the malicious traffic mimics legitimate remote work. Once inside, attackers can steal credentials, move laterally between systems, exfiltrate data, or deploy ransomware before detection.

Details of the Authentication Bypass

Palo Alto disclosed CVE-2026-0257 on May 13, 2026. It is rated “High” severity with a CVSS score of 7.8. The flaw allows attackers, even without valid login credentials, to bypass authentication and initiate GlobalProtect VPN connections under specific configurations. Crucially, vulnerability arises when authentication override cookies are enabled alongside certain certificate setups—cookies that are intended to link GlobalProtect portal and gateway components but are improperly validated or integrity-checked.

Not all Palo Alto deployments are vulnerable. Affected versions include releases of PAN-OS 12.1, 11.2, 11.1, and 10.2; also Prisma Access 11.2 and 10.2. Panorama and Cloud NGFW systems are not impacted. Administrators are urged to check not only the main version numbers, but also specific maintenance releases, since the patch status varies per build.

What Organizations Should Do Now

The first priority is applying the latest security updates to all affected GlobalProtect portals and gateways—both internal and external. Hybrid deployments using on-premises firewalls with Prisma Access must also be updated. Administrators should disable authentication override cookies where they are not absolutely necessary, and generate a new certificate solely for any remaining override-cookie functionality. Reusing certificates used elsewhere is discouraged.

After patching, organizations must terminate all active GlobalProtect sessions to cut off any persistent access. Review should include unexpected sessions, especially those tied to suspicious device names like “kali,” which may indicate misuse. It’s essential to assume that compromised access could persist unless cleaned up. Security teams are also advised to analyze what happens after a VPN connection—not just whether it succeeds—but what actions follow.

ReliaQuest predicts that exploitation of this flaw will remain a significant risk at least over the next three months, as threat actors and initial access brokers target unpatched systems. Exposed gateways should be scoped for mitigation with highest urgency, while teams hunt for evidence of past unauthorized access.

This issue underscores the growing pattern of ransomware groups attacking VPN services—which are often viewed as high-value targets due to their role in remote access. It highlights why organizations can’t rest at “patch applied” but must also audit post-authentication behavior and session lifecycles.