ReliaQuest: Qilin and Settra enter networks via GlobalProtect without credentials
ReliaQuest reports active exploitation of CVE-2026-0257, an authentication-bypass flaw in PAN-OS GlobalProtect and Prisma Access. Exploitation requires enabled authentication override cookies and a specific certificate setting; Palo Alto Networks rates it high severity and urges updates for PAN-OS 12.1, 11.2, 11.1, 10.2 and Prisma Access 11.2, 10.2.
- CVE-2026-0257 is an authentication bypass in PAN-OS GlobalProtect and Prisma Access
- Affected: PAN-OS 12.1, 11.2, 11.1, 10.2 and Prisma Access 11.2, 10.2
- Exploitation needs authentication override cookies and a specific certificate setting
- ReliaQuest expects attacks to continue over the next three months
Read next
Security