Cybersecurity Threat Advisory 29-26: Qilin exploits GlobalProtect flaw
Threat update
An authentication bypass zero-day vulnerability, tracked as CVE-2026-20182 with a maximum CVSS score of 10.0, has been identified in Cisco Catalyst SD-WAN Controller and Manager. The vulnerability allows unauthenticated attackers to gain the highest level of administrative access to affected systems without valid credentials and is currently under active exploitation by UAT-8616, a persistent and sophisticated threat group previously linked to multiple zero-day campaigns targeting Cisco network edge technologies. Continue reading this Cybersecurity Threat Advisory to learn how to minimize your risk and protect your environment.
Technical Detail and Additional Info
What is the threat?
CVE-2026-0257 affects GlobalProtect portals and gateways under certain configurations. The flaw can allow an attacker to establish a VPN session without valid credentials, making the connection appear legitimate. The vulnerability affects PAN-OS 12.1, 11.2, 11.1, and 10.2 versions released before Palo Alto's fixes, along with certain Prisma Access deployments.
After gaining access, Qilin operators establish persistence, deploy remote access tools such as AnyDesk, Ngrok, and LogMeIn, harvest credentials, and extract Active Directory data. They then move laterally through the environment and deploy ransomware after disabling security controls and clearing logs
Why is it noteworthy?
This vulnerability allows attackers to gain trusted VPN access without credentials, bypassing controls that typically rely on user authentication and MFA. Researchers have linked the activity to the Qilin ransomware-as-a-service (RaaS) operation. As a result, multiple threat actors may adopt the exploit. Once inside, attackers can steal credentials, exfiltrate data, move laterally, and deploy ransomware. This creates significant risk for organizations with exposed GlobalProtect environments.
What is the exposure or risk?
Organizations running vulnerable PAN-OS or Prisma Access systems with internet-facing GlobalProtect services are at high risk. Successful exploitation gives attackers access to internal systems, including servers, administrative interfaces, and domain controllers. They may steal credentials, extract Active Directory data, install persistence mechanisms, exfiltrate sensitive information, and ultimately deploy ransomware across the environment.
Attackers also use cloud storage services to hold stolen data. They often disable Microsoft Defender and clear event logs to hinder detection and investigation. Even after patching, organizations remain at risk if they do not terminate active VPN sessions or reset compromised credentials.
What are the recommendations?
LBT Technology Group the following actions to secure your network infrastructure:
- Patch all affected PAN-OS and Prisma Access systems immediately.
- Terminate all active GlobalProtect VPN sessions after patching.
- Review GlobalProtect configurations, including authentication override cookies and certificate settings, and align them with Palo Alto best practices.
- Reset privileged and domain credentials if compromise is suspected and enforce MFA for VPN and administrative access.
- Monitor for suspicious activity involving tools such as PsExec, AnyDesk, Ngrok, LogMeIn, Rclone, rundll32.exe, comsvcs.dll, and ntdsutil.exe.
- Send logs to a centralized SIEM or logging platform to preserve visibility if local logs are deleted.
- Restrict VPN access and apply least-privilege access controls to sensitive systems.
References
For more in-depth information about the recommendations, please visit the following links:
