Another corporate VPN gateway, another ransomware gang walking through the front door. Arctic Wolf Labs published research on July 20, 2026, detailing intrusions throughout June that trace back to CVE-2026-0257, a critical authentication bypass in Palo Alto Networks’ GlobalProtect VPN, culminating in Qilin ransomware deployment on victim networks.

If the pattern sounds familiar, that’s because it is. This is at least the third major corporate VPN gateway flaw this year alone to end in a ransomware payload, following incidents involving Check Point and SonicWall appliances. It’s worth being precise about what broke, who’s affected, and whether it says anything about the VPN you use to watch Netflix.

What CVE-2026-0257 actually does

The flaw sits in specific GlobalProtect configurations where authentication override cookies are enabled. According to BleepingComputer’s reporting, it lets an attacker establish an unauthorized VPN session without valid credentials, effectively walking past the login step entirely under those configurations.

Palo Alto Networks patched the underlying issue on May 13, 2026. Rapid7 observed broad exploitation beginning just four days later, on May 17. CISA added the flaw to its Known Exploited Vulnerabilities catalog on May 29, which requires US federal agencies to patch on a mandated timeline. Arctic Wolf’s July 20 report describes intrusions specifically during June that used this access to deploy Qilin ransomware, meaning attackers were actively exploiting the flaw for weeks after both a patch and a federal mandate existed.

Who’s behind it

Qilin has been one of the most active ransomware-as-a-service operations of the past two years, and its affiliates have repeatedly shown a preference for exploiting edge devices, firewalls, VPN gateways, and other internet-facing infrastructure, rather than the more traditional route of phishing individual employees. Security researchers describe this as an efficient trade for attackers: a single unpatched gateway can grant direct access to an entire corporate network, without needing a single employee to click anything.

Threat monitoring services have flagged well over 100,000 GlobalProtect instances exposed to the internet at various points during this exploitation window, giving Qilin affiliates a large pool of potential targets to scan against.

Timeline: from patch to ransomware payload

The gap between “patched” and “actively exploited by ransomware” was short, and it’s worth laying out plainly.

DateEvent
May 13, 2026Palo Alto Networks releases the patch for CVE-2026-0257
May 17, 2026Rapid7 observes broad exploitation beginning
May 29, 2026CISA adds the flaw to its Known Exploited Vulnerabilities catalog
June 2026Arctic Wolf Labs documents intrusions culminating in Qilin ransomware deployment
July 20, 2026Arctic Wolf publishes its findings publicly

Sixteen days separated the patch from broad exploitation. That’s a narrow window for organizations to patch before attackers start scanning for unpatched instances, and it’s a pattern that keeps repeating across this category of hardware: SonicWall’s SMA1000 devices faced a similarly compressed timeline earlier this year.

Why this is a corporate story, not a consumer VPN story

It’s worth being direct about this, because stories like this reliably get flattened into “VPNs are unsafe” whenever they circulate. They aren’t describing the same product.

GlobalProtect is a corporate remote-access VPN. Organizations run it as a gateway that accepts inbound connections from employees working remotely, and its entire job is authentication: deciding who gets into the company network and who doesn’t. When that authentication step fails, as CVE-2026-0257 demonstrates, attackers get inside a network full of servers, employee data, and everything else worth encrypting for ransom.

A consumer VPN like the ones we compare and rank works in the opposite direction. You make an outbound connection from your device to the provider’s server to encrypt your own traffic on its way to the wider internet. There’s no corporate network sitting behind a consumer VPN app, and nothing structurally similar for ransomware to reach. We made the same distinction when covering the Check Point IKEv1 zero-day exploited by another Qilin-linked affiliate earlier this year: the acronym is identical, the product category and attack surface are not.

Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.

The pattern worth actually paying attention to

Treat each individual CVE as less important than the broader pattern: enterprise VPN and firewall gateways have become one of the most consistently targeted categories of infrastructure for ransomware affiliates, precisely because they sit exposed to the internet by design and grant deep access when compromised. This is the same underlying dynamic covered in our piece on why enterprise VPN gateways keep getting breached, and Palo Alto’s GlobalProtect flaw is simply the newest entry in that pattern, not an isolated event.

For IT teams running any of this class of hardware, the practical lesson isn’t “patch this one CVE” so much as “assume every internet-facing VPN gateway is an active target, and patch on the CISA-mandated timeline rather than a slower internal schedule.” Organizations that treated the May 29 CISA deadline as a hard cutoff avoided the June intrusions Arctic Wolf documented; organizations that didn’t, generally didn’t.

What IT teams running GlobalProtect should do now

If your organization runs GlobalProtect and hasn’t confirmed the May 13 patch is applied, that’s the first and most urgent step, ahead of anything else. Beyond patching, Palo Alto’s own advisory recommends reviewing whether authentication override cookies are enabled in your configuration at all, since disabling that specific setting removes the exposed condition even before a patch is confirmed applied everywhere.

Security teams should also treat any GlobalProtect gateway that was internet-facing and unpatched between May 17 and the confirmed patch date as potentially compromised, not just vulnerable, and review logs from that window specifically for the kind of unauthenticated session establishment Arctic Wolf describes. Given Qilin’s documented pattern of using compromised gateway access to move laterally before deploying ransomware, a clean bill of health on the gateway itself doesn’t rule out deeper compromise if the window of exposure was long enough.

What this means if you’re a home user

Nothing changes about the safety of the consumer VPN sitting in front of you unblocking a streaming service or encrypting your coffee-shop Wi-Fi connection. Nothing about this vulnerability, its exploitation, or the Qilin ransomware payload touches consumer VPN infrastructure at all. If you want to understand the broader difference between the two categories of product that share a name, our explainer on VPN vs zero trust architecture covers how corporate remote-access security has been evolving specifically because of incidents like this one.

Our verdict

CVE-2026-0257 is a serious, actively exploited flaw in Palo Alto's GlobalProtect corporate VPN, patched in May, exploited through June, and publicly detailed by Arctic Wolf Labs on July 20. It's the latest in a string of enterprise VPN gateway breaches this year and a legitimate concern for any organization running GlobalProtect on the affected configuration. It has no bearing on consumer VPN products, which work on fundamentally different infrastructure with no equivalent attack surface.

For more on how corporate and consumer VPNs differ structurally, see who really owns your VPN.