Qilin ransomware affiliates are using a patched PAN-OS auth bypass as their front door
Arctic Wolf Labs traced multiple June 2026 Qilin ransomware intrusions to a patched Palo Alto Networks PAN-OS flaw that lets attackers establish a VPN session without valid credentials when authentication override cookies are misconfigured.
Arctic Wolf Labs documented multiple intrusions in June 2026 in which Qilin (also tracked as Agenda) ransomware affiliates gained initial access by exploiting CVE-2026-0257 (CVSS 7.8), a now-patched flaw in Palo Alto Networks PAN-OS portal and gateway components. The bug lets an unauthenticated remote attacker sidestep authentication entirely and establish a working VPN session without valid credentials, when authentication override cookies are enabled alongside specific certificate configurations. Post-exploitation tactics varied across the intrusions Arctic Wolf reviewed, from fast encryption-only runs to full double-extortion campaigns with data exfiltration, a pattern consistent with multiple ransomware-as-a-service affiliates using the same entry point independently. Common tradecraft included staging payloads in C:\PerfLogs, PsExec for lateral movement, password-protected payloads, and log clearing.
Why it matters
An authentication bypass on a VPN gateway is worse than a stolen credential in one specific way: there's no compromised account to disable, no password to rotate, because the attacker never needed one. That's what makes it a clean initial-access vector for multiple unaffiliated ransomware crews to reuse against the same unpatched population.
If you run PAN-OS with authentication override cookies enabled, patching alone doesn't tell you whether you were already hit in the window before the fix; check for the staging and lateral-movement pattern Arctic Wolf documented, not just patch status.
Source: The Hacker News
Related on Start with Identity
- BlogEvery on-premises TeamCity server is vulnerable to an auth bypass in the agent polling protocol
CVE-2026-63077 lets an unauthenticated attacker abuse TeamCity's agent polling protocol to bypass authentication and run arbitrary OS commands with the server p
- BlogFortinet's January SSO bypass hit boxes already patched for December's SAML bug
CVE-2026-24858 is the follow-on FortiCloud SSO SAML bypass. Devices patched for CVE-2025-59718 and 59719 were still exploitable. Actively exploited. CISA guidan
- BlogN-able confirms attackers used an N-central auth bypass to reach managed customer networks
CVE-2026-18577 gave unauthenticated attackers full administrative control of N-central, which they used through the Take Control feature to reach downstream man
- CVEConnectWise ScreenConnect auth bypass via an alternate path
ScreenConnect 23.9.7 and earlier skipped authentication on an alternate setup path (CWE-288). Attackers created admin users within hours. CISA KEV. CVSS 10.0. P
- CVEDrupal Simple OAuth/OIDC auth bypass via an alternate path
Drupal Simple OAuth / OIDC 6.0.0 through 6.0.6 allowed authentication to be skipped on an alternate path. Patched in 6.0.7.
- CVEFortiWeb auth bypass and path traversal, admin creation
FortiWeb authentication bypass plus path traversal that lets an attacker create an admin. CVSS 9.8. Added to CISA KEV around 14 November 2025, before the Decemb