Palo Alto Networks Flaw CVE-2026-0257 Exploited to Deploy Qilin Ransomware
A high-severity authentication bypass vulnerability in **Palo Alto Networks**' **PAN-OS** software, **CVE-2026-0257**, has been actively exploited by threat actors to gain initial access and deploy **Qilin** (also known as **Agenda**) ransomware. Cybersecurity firm **Arctic Wolf Labs** observed multiple intrusions leveraging this flaw, highlighting the evolving tactics of ransomware-as-a-service (RaaS) affiliates.

Threat actors have been observed exploiting a now-patched high-severity **Palo Alto Networks PAN-OS** vulnerability as an entry point to deploy **Qilin** (aka **Agenda**) ransomware on victim environments.
**Arctic Wolf Labs** reported investigating multiple intrusions in June 2026 that commenced with the exploitation of **CVE-2026-0257** (CVSS score: 7.8). This authentication bypass flaw impacts the portal and gateway components of **PAN-OS** software.
### The Vulnerability and Initial Access
Successful exploitation of **CVE-2026-0257** allows unauthenticated remote attackers to bypass authentication and establish VPN sessions without valid credentials, particularly when authentication override cookies are enabled with specific certificate configurations.
"Post-exploitation tradecraft varied across intrusions, from rapid encryption-only operations to full double-extortion, possibly suggesting multiple affiliates operating under the **Qilin** ransomware-as-a-service (RaaS) umbrella," the cybersecurity company stated.
### Post-Exploitation Tactics
Attackers demonstrated consistent operational patterns despite variations in their tradecraft. These patterns included staging ransomware at `C:\PerfLogs\`, utilizing **PsExec** for lateral execution via administrative shares, deploying password-protected ransomware payloads, and implementing comprehensive log-clearing routines.

### Escalation and Evasion
The threat actors weaponized the flaw to gain authenticated access to victim networks by establishing SSL VPN sessions. Following this initial breach, they escalated their attacks to facilitate credential harvesting and lateral movement through Windows administrative shares via compromised administrative accounts.
The activity was also characterized by attackers taking deliberate steps to clear event logs and disable **Microsoft Defender Real-Time Protection** prior to running the ransomware payload. This aims to minimize detection and avoid leaving forensic evidence.
### RaaS Model Variability
Despite similarities in ransomware staging paths, **PsExec**-based execution, and an unusual Windows Registry persistence pattern (i.e., an asterisk followed by six randomized lowercase alphabetic characters), follow-on attacks varied across victims. This ranged from enterprise-wide encryption with no data exfiltration and extensive reconnaissance via remote access tools like **AnyDesk**, **Ngrok**, or **LogMeIn**, to large-scale credential theft and instances of data exfiltration to the **MEGA** cloud service before ransomware deployment using **Rclone**, **Proton Drive**, and **FileZilla**.
"This variability is consistent with RaaS models, in which multiple affiliates may leverage shared initial access infrastructure and ransomware tooling while applying their own preferred post-exploitation methodologies," **Arctic Wolf** concluded.