GlobalProtect Authentication Bypass: A Checklist While Qilin Ransomware Still Exploits It

by Rebecca Sutton

If your business runs a Palo Alto Networks firewall for remote access, there is a specific check to make this week. A GlobalProtect authentication bypass, CVE-2026-0257, was patched back in May. Qilin ransomware affiliates are still using it. They get into networks with no username, no password and no MFA code. Arctic Wolf Labs published new findings on 20 July. The attacks are still going on.

What the GlobalProtect authentication bypass actually does

GlobalProtect has an optional feature called authentication override. It issues a cookie so a user does not have to log in again each session. Think of it like a browser that keeps you signed into a website. The flaw lets an attacker forge that cookie. The forgery skips the login step entirely. None of your normal authentication controls get a chance to fire, MFA included.

The feature is off by default. Plenty of firms turn it on anyway, for ease of use. Staff often connect from a mix of laptops and phones, and login prompts get annoying fast. If the feature is on in your setup, you are at risk. That is true even if you patched other PAN-OS issues this year. This is a separate flaw. It has its own fix and its own version numbers.

Palo Alto Networks rates it 7.8 out of 10: high, not critical. But a score does not show what happens next. An attacker who forges the cookie gets a working VPN session. To most tools watching the network, it looks like a real one. That is the foothold Qilin affiliates have used since at least June.

IT team member typing at a laptop while checking GlobalProtect authentication bypass patch status

Step one: confirm the patch, not just the ticket

Palo Alto Networks fixed this in mid-May. The fix covers PAN-OS 10.2, 11.1, 11.2 and 12.1, plus Prisma Access. A change ticket that says “PAN-OS patched” is not proof. Check the exact build number yourself, against Palo Alto’s advisory. Look for these builds or later: 10.2.7-h34, 10.2.18-h6, 11.1.4-h33, 11.1.15, 11.2.4-h17, 11.2.12, 12.1.4-h6, or 12.1.7.

Cloud NGFW is not affected, so if that is your only exposure, you can stand down. Everyone else should treat this as a live gap until the version check comes back clean. Rapid7 confirmed live attacks against customers within days of the advisory. CISA added the flaw to its Known Exploited Vulnerabilities list on 29 May, with a three-day deadline for federal agencies. This moved from disclosure to active attack faster than most patch cycles complete.

Step two: if you cannot patch today

Can’t patch the GlobalProtect authentication bypass right away? Two mitigations buy you time without an upgrade window. First, disable authentication override on the portal and gateway if you do not strictly need it. Second, if you do need it, issue a certificate used only for authentication override cookies, not one shared with other services. Palo Alto’s advisory sets out both options in detail.

Expect one round of forced re-authentication for your users after you apply the fix. The patch regenerates cookies using a stronger method. Warn your service desk first, so it does not look like a fresh incident.

Step three: look for signs you were already hit

The GlobalProtect authentication bypass does not show up in login logs the way a stolen password would. So hunting back through your logs matters more than usual. Arctic Wolf looked into a string of Qilin break-ins that used this route. It found a repeatable pattern. Check your own logs for:

  • VPN sessions from hosts self-identifying as “kali”, an unusual client string for a legitimate user
  • New registry Run key entries created around the time of an unexplained VPN session
  • LSASS memory access via rundll32.exe calling comsvcs.dll, used to harvest credentials
  • ntdsutil.exe activity against a domain controller, used to pull the Active Directory database
  • PsExec sessions or administrative share (C$) activity that your team did not schedule
  • Windows event logs cleared in bulk via PowerShell, and Defender’s real-time protection switched off
  • Unfamiliar remote access tools on endpoints, such as AnyDesk, Ngrok, LogMeIn or MeshAgent, none of which are standard on a typical SME estate

Any one of these could have an innocent explanation on its own. But two or more together, especially after an unexplained VPN connection, warrant an incident response call. Not a routine ticket.

Don’t assume a small business isn’t a target

It is tempting to read a story about a named ransomware group and a global vendor and assume the risk sits with large enterprises. It does not work that way here. Shadowserver counts more than 167,000 GlobalProtect instances still reachable from the internet. Arctic Wolf’s cases span a range of business sizes, not just headline-grabbing victims. Ransomware affiliates scan for the weak setup at random. They do not check your headcount before they try the cookie forgery.

For a UK small or mid-sized business, the same check applies whether you have five staff on VPN or five hundred. If GlobalProtect is your remote access route in, the patch and the log review above are not optional extras. They are this week’s task. Not confident which of your internet-facing systems carry the GlobalProtect authentication bypass risk? An external network penetration test or a routine vulnerability scan will surface it faster than waiting for the next headline.

Why the GlobalProtect authentication bypass keeps working

CISA added CVE-2026-0257 to its Known Exploited Vulnerabilities list on 29 May. Federal agencies had three days to act. Two months on, Shadowserver still counts more than 167,000 GlobalProtect boxes open to the internet. Arctic Wolf is still finding new victims, as of its latest report on 20 July. The gap between a patch going out and a fleet actually being current is where crews like Qilin thrive. Edge devices such as VPN gateways sit at the front of that queue, because they are internet-facing by design.

None of this means the disclosure process failed. Palo Alto Networks published a clear advisory. Rapid7 and Arctic Wolf both moved fast to document the attacks. CISA acted fast too. What is missing is the last step: someone on your side actually checking the fix landed on every exposed device. Not just the ones that came up in the next scheduled maintenance window.

Subscribe to our newsletter

Honest updates, straight to your inbox. Unsubscribe any time.

You may also like