Ransomware groups are actively exploiting CVE-2026-0257, an authentication bypass affecting Palo Alto Networks PAN-OS GlobalProtect and Prisma Access. ReliaQuest reports that multiple threat groups, including Qilin and Settra, are using the flaw to create unauthorized VPN sessions and enter internal networks through trusted remote access services.
The activity presents a serious detection challenge because attackers connect through an organization’s own VPN. Their traffic can look like normal remote work, giving them time to steal credentials, move between systems, collect sensitive data, or prepare ransomware before security teams recognize the intrusion.
In its threat update, ReliaQuest also reported related activity involving Cobalt Strike, BloodHound, and SharpHound. These observations show that defenders must investigate what happens after a suspicious VPN connection, rather than treating the successful connection itself as proof that the user is legitimate.
GlobalProtect Authentication Bypass
Palo Alto Networks disclosed the vulnerability on May 13, 2026. Its security advisory assigns a CVSS score of 7.8 and a High severity rating, with the highest suggested response urgency. The issue allows an attacker without valid credentials to bypass security restrictions and establish an unauthorized VPN connection.
Exposure depends on configuration. A GlobalProtect portal or gateway must have authentication override cookies enabled alongside a specific certificate configuration. These cookies support authentication across GlobalProtect components, but the vulnerability involves reliance on cookies without proper validation and integrity checks. Not every Palo Alto Networks deployment is affected.
The advisory lists affected releases across PAN-OS 12.1, 11.2, 11.1, and 10.2, together with Prisma Access 11.2 and 10.2. Panorama and Cloud NGFW are not affected. Administrators should check their exact maintenance release against the vendor’s fixed version table rather than relying only on the main version number.
Earlier reporting on Qilin exploiting CVE-2026-0257 described intrusions that progressed from unauthorized VPN access to credential theft and ransomware deployment. ReliaQuest’s observations now identify Settra alongside Qilin, reinforcing that exploitation is not limited to a single ransomware operation.
Organizations should immediately upgrade affected deployments and disable authentication override cookies where they are unnecessary. Palo Alto Networks also recommends a newly generated certificate dedicated exclusively to authentication override cookies. Administrators should not reuse a portal or gateway certificate, or a certificate previously used for another service.
Updates must cover all internal and external GlobalProtect portals and gateways that generate or accept authentication cookies. Hybrid Prisma Access environments also require upgrades to affected on-premises firewalls. The vendor warns that incomplete upgrades can create cookie compatibility problems between components. Users must authenticate again after the patched software changes cookie generation.
ReliaQuest recommends terminating all active GlobalProtect sessions after patching and investigating unexpected connections, including devices using hostnames such as “kali.” Such a hostname is an investigation lead, not standalone proof of compromise. Patching alone may not remove access established before remediation, making session cleanup and follow-up investigation essential.
The warning fits broader ransomware attacks targeting VPN services. ReliaQuest assesses that exploitation is highly likely to continue over the next three months as ransomware groups and initial access brokers pursue unpatched systems. Defenders should prioritize exposed gateways while checking for access gained before fixes were applied.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

