'Perimeter defences are prime targets': Security experts issue alert over Palo Alto GlobalProtect VPN exploitation
The flaw in Palo Alto Networks’ GlobalProtect VPN was recently upgraded from a ‘medium’ rating to ‘high’
Cyber experts have urged users of Palo Alto Networks' GlobalProtect VPN to patch immediately amidst active exploitation of an upgraded security flaw.
A flaw in the popular VPN service, tracked as CVE-2026-0257, could allow attackers to bypass authentication and establish an unauthorized connection.
The vulnerability primarily affects the GlobalProtect portal and gateway for Palo Alto Networks’ PAN-OS software, and carries a CVSS score of 7.8, rating it as ‘high’ in severity.
Notably, this rating follows an upgrade, with the flaw having previously been given a ‘medium’ severity rating. Palo Alto announced the upgrade late last week amidst reports that the flaw was now being exploited in the wild.
“Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied,” the company said in an advisory.
Analysis by Rapid7 shows threat actors have been exploiting the vulnerability since mid-May across several waves of attacks.
“Rapid7 MDR identified successful exploitation across numerous customers; however, we did not observe any indication of successful lateral movement from the devices,” researchers said.
“The earliest date for observed exploitation was May 17, 2026. As of May 29, 2026, this vulnerability has been added to the CISA KEV.”
Rapid7 noted that customers compromised in this wave of attacks had Cloud Authentication Service (CAS) disabled. Others, meanwhile, had GlobalProtect portal or gateway authentication override cookies enabled.
A patch has been issued for customers running affected appliances, according to Palo Alto.
Similarly, administrators are advised to turn off authentication override features to mitigate potential exploitation.
Qilin ransomware involved in GlobalProtect attacks
Analysis by Arctic Wolf Labs suggests attacks on GlobalProtect customers could be the work of the Qilin ransomware group or affiliates. Indeed, researchers detected Qilin ransomware during several instances across June, highlighting a range of tell-tale signs.
“Post-exploitation tradecraft varies across intrusions, from rapid encryption-only operations to full double extortion, possibly suggesting multiple affiliates operating under the Qilin ransomware as a service (RaaS) umbrella,” the company said.
Dray Agha, senior manager for Huntress’ security operations center, said these attacks highlight the growing threats posed to VPNs and firewalls.
"The exploitation of this GlobalProtect vulnerability by the Qilin ransomware gang demonstrates that perimeter defences are prime targets,” he said.
“When threat actors can bypass VPN authentication, they are walking through the digital front door with a master key. The grace period for patching critical edge devices has practically vanished, and they must be the patching priority for all organizations".
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.

Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.
He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.
For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.
-
NetApp snaps up DataPelago to bolster AI data infrastructure portfolioNews The acquisition brings GPU-accelerated data processing into NetApp's storage layer to help customers speed up AI workloads
-
How AI certification can help employees to climb the career ladderIn depth Research shows that validating AI knowledge and skills can help to boost job mobility and salaries
-
‘The risk to every organization has increased exponentially’: The FortiBleed campaign just took a turn for the worseNews Reports suggest that FortiBleed-linked exposed credentials could put UK government and public services at huge risk
-
‘Traditional patching cannot keep pace’: Palo Alto Networks joins IBM’s Project Lightwell in bid to shore up software securityNews With traditional patching no longer able to keep pace with threats, the trio aims to create an automated "shield-and-fix" architecture
-
How to MFA everywhereIndustry Insights Identity online is not who you are; it is what the system accepts as proof of you, and that gap is exactly what the attackers take advantage of
-
What role does a VPN play in modern business?Sponsored Businesses wanting to protect sensitive data need to consider how they protect their data in motion as well as at rest
-
Cisco ASA customers urged to take immediate action as NCSC, CISA issue critical vulnerability warningsNews Cisco customers are urged to upgrade and secure systems immediately
-
SonicWall launches new firewalls as part of Generation 8 refreshNews The vendor’s latest update includes unified management and integrated ZTNA, backed by embedded warranty and co-managed services
-
ExpressVPN updates Windows app to fix vulnerabilityNews The flaw was reported through ExpressVPN's bug bounty program
-
Okta and Palo Alto Networks are teaming up to ‘fight AI with AI’News The expanded partnership aims to help shore up identity security as attackers increasingly target user credentials