chiprook
← Security
SecurityOctober 11, 2026, 10:34

ReliaQuest: Qilin and Settra enter networks via GlobalProtect without credentials

ReliaQuest reports active exploitation of CVE-2026-0257, an authentication-bypass flaw in PAN-OS GlobalProtect and Prisma Access. Exploitation requires enabled authentication override cookies and a specific certificate setting; Palo Alto Networks rates it high severity and urges updates for PAN-OS 12.1, 11.2, 11.1, 10.2 and Prisma Access 11.2, 10.2.

ReliaQuest: Qilin and Settra enter networks via GlobalProtect without credentials
#PaloAltoNetworks#GlobalProtect#PrismaAccess#ReliaQuest
Read next
Security

New Settra ransomware variant hits retail and manufacturing

Security

Japan extradites suspected Qilin ransomware operative to Germany

Security

Palo Alto Networks: 52% of critical infrastructure operators can't see legacy OT

Security

Palo Alto Networks and NVIDIA tighten control over AI agents