Back to Blog
CVE-2026-0257: Palo Alto Networks PAN-OS — Ransomware via Auth Bypass (June 2026)
vulnerabilities

CVE-2026-0257: Palo Alto Networks PAN-OS — Ransomware via Auth Bypass (June 2026)

breachwire TeamJul 22, 20262 min read

CVE-2026-0257 — Palo Alto Networks PAN-OS

CVE-2026-0257 is a high-severity authentication bypass vulnerability in Palo Alto Networks PAN-OS, actively exploited in June 2026 with a CVSS score of 8.8. Attackers leveraged this flaw to gain unauthorized VPN access, escalate privileges, and deploy Qilin (Agenda) ransomware in enterprise environments. The vulnerability was patched prior to the attacks, but unpatched systems remain at immediate risk.

Attack Vector

Threat actors exploited CVE-2026-0257 to bypass authentication controls on exposed PAN-OS VPN interfaces. After gaining initial access, they escalated privileges and harvested credentials, then used PsExec for lateral movement across Windows hosts. Ransomware payloads were staged at C:\PerfLogs\ and deployed using password protection to evade detection. Persistence was established via Windows Registry entries with a pattern of an asterisk followed by six random lowercase characters. Attackers used remote access tools (AnyDesk, Ngrok, LogMeIn) for reconnaissance and exfiltrated data to MEGA, Rclone, Proton Drive, and FileZilla. Defensive measures were disabled and logs were cleared to hinder response.

Who Is at Risk

All organizations running unpatched Palo Alto Networks PAN-OS are at risk, especially those exposing VPN interfaces to the internet. Confirmed victims include global enterprises using affected PAN-OS versions. Environments with weak credential hygiene or insufficient monitoring are particularly vulnerable to lateral movement and data exfiltration.

Patch & Mitigate

  • Patch: Upgrade to the fixed PAN-OS version released by Palo Alto Networks immediately. Refer to official advisories for version-specific details.
  • Workaround: Restrict management and VPN interface exposure to trusted networks only; enforce MFA where possible.
  • Detect: Monitor for PsExec usage, new files in C:\PerfLogs\, suspicious registry entries (asterisk + 6 random lowercase characters), unauthorized remote access tools, and outbound connections to MEGA, Rclone, Proton Drive, or FileZilla.

MITRE ATT&CK

  • TA0001 — Initial Access: Exploitation of PAN-OS authentication bypass for VPN entry.
  • TA0003 — Persistence: Registry modifications for ransomware persistence.
  • TA0005 — Defense Evasion: Log clearing and disabling security controls post-compromise.

Source: https://thehackernews.com/2026/07/qilin-ransomware-attackers-exploit-pan.html

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: