A coordinated wave of exploitation targeting edge VPN and firewall appliances from four major vendors Palo Alto Networks, Fortinet, Citrix, and Check Point has emerged as the dominant initial-access vector for ransomware operators in mid-2026.
Threat actors, including affiliates of the Qilin ransomware-as-a-service (RaaS) operation, are chaining authentication-bypass flaws, credential-harvesting campaigns, and legacy-protocol weaknesses to obtain unauthenticated or credential-free access to corporate perimeters.
Once inside, these actors move rapidly toward lateral movement, data exfiltration, and double-extortion ransomware deployment, often within days of a CVE’s public disclosure.
The campaigns analyzed here span four separate but converging incidents: the “Fortibleed” mass credential-compromise campaign against roughly 75,000 internet-facing FortiGate firewalls; active exploitation of the Palo Alto GlobalProtect authentication-bypass flaw CVE-2026-0257; Qilin-linked exploitation of the Check Point VPN authentication-bypass flaw CVE-2026-50751 tied to the deprecated IKEv1 protocol; and rapid in-the-wild abuse of a new CitrixBleed-style NetScaler memory-disclosure bug, CVE-2026-8451.
Each incident underscores the same operational reality: internet-facing remote access infrastructure has become the ransomware ecosystem’s preferred front door.
Enterprise VPN and firewall appliances sit at the network edge, are internet-reachable by design, and frequently run outdated firmware or legacy protocols that organizations are reluctant to disable due to compatibility concerns.
This combination makes them attractive to ransomware affiliates who prize a fast, low-noise route into a target’s internal network without triggering endpoint detection tools.
Successful authentication bypass or credential theft against a VPN concentrator lets an attacker walk in as a “legitimate” remote user, sidestepping most perimeter-focused security controls entirely.
The speed of weaponization has also compressed dramatically. Attackers exploited the Palo Alto GlobalProtect flaw within days of public proof-of-concept code being released, and exploitation attempts against the Citrix NetScaler flaw began less than 24 hours after Citrix’s July 2026 disclosure. This near-immediate exploitation window leaves defenders very little time between patch release and active abuse.
Fortibleed is a large-scale credential-harvesting campaign, first identified in mid-June 2026, in which threat actors systematically extracted configuration files from internet-facing Fortinet FortiGate firewalls and cracked the stored password hashes.
Independent analysis by Kevin Beaumont, Hudson Rock, and SOCRadar found working administrator and SSL VPN credentials for between roughly 30,791 and 75,000 devices spanning 194 countries and more than 21,000 domains, approximately half of all internet-facing FortiGate appliances visible on Shodan.
Unlike a single-CVE exploit chain, Fortibleed reflects the cumulative effect of previously known FortiOS credential-storage weaknesses combined with weak or reused passwords and unpatched appliances left exposed to the internet.
Researchers warn that any organization appearing in the exposed dataset should treat its network perimeter as already compromised.
Takeaway for Defenders:
Palo Alto Networks disclosed CVE-2026-0257 on May 13, 2026, describing an authentication-bypass vulnerability (CWE-565) in the GlobalProtect portal and gateway components of PAN-OS.
The flaw stems from PAN-OS trusting any authentication override cookie it can decrypt without verifying the cookie was legitimately generated by the device; if the same certificate is reused for the GlobalProtect HTTPS service and cookie encryption, an attacker can retrieve the certificate chain from the public HTTPS service and forge valid cookies for any user, including administrators.
Exploitation requires three conditions: GlobalProtect portal or gateway enabled, authentication override cookies enabled (not default), and certificate reuse or exposure.
Rapid7 published a working proof-of-concept on May 29, 2026, prompting Palo Alto to raise the CVSS score from an initial 4.7 to 7.8, and CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog the same day.
Active exploitation has been confirmed as far back as May 17, 2026. By July 2026, Qilin ransomware affiliates were confirmed abusing this flaw to gain unauthorized VPN access to unpatched networks.
In observed intrusions, threat actors forged authentication override cookies for privileged accounts, including default “admin” accounts, to establish VPN sessions without credentials or MFA, then used post-exploitation tools such as Impacket and NTLM relay attacks for configuration retrieval, IPsec tunnel establishment, and lateral movement.
Affected products: PA-Series and VM-Series firewalls and Prisma Access running PAN-OS with GlobalProtect enabled and authentication override cookies configured. Cloud NGFW is not affected.
Remediation:
Check Point disclosed CVE-2026-50751 (CVSS 9.3) on June 8, 2026, warning of active exploitation of a logic-flow weakness in certificate validation affecting Remote Access VPN and Mobile Access deployments configured to use the deprecated IKEv1 key-exchange protocol.
The flaw allows an unauthenticated remote attacker to bypass user authentication and establish a VPN session without a valid password.
Exploitation requires several conditions to align: VPN Remote Access or Mobile Access enabled, IKEv1 enabled for remote access, gateways accepting legacy Remote Access clients, and no machine-certificate requirement. Check Point confirmed that attacks against the flaw began as early as May 7, 2026, a full month before public disclosure, and picked up pace in early June.
Critically, Check Point confirmed that a Qilin ransomware affiliate exploited the vulnerability in post-compromise activity against victim organizations. WatchTowr Labs later detailed how attackers manipulated authentication flags via a custom VPNExtFeatures Vendor ID payload during IKEv1 negotiation to achieve full authentication bypass.
A related flaw, CVE-2026-50752 (CVSS 7.4), affects certificate validation in IKEv1 and could enable adversary-in-the-middle attacks against site-to-site VPN connections, though no in-the-wild exploitation of this second bug has been confirmed.
Affected products: Security Gateways R82.10 JHF Take 19 or below, R82 JHF Take 103 or below, R81.20 JHF Take 141 or below, R81.10/R81/R80.40 (all end-of-support), and Spark Firewalls R80.20.X/R81.10.X/R82.00.X.
Remediation:
Citrix disclosed six vulnerabilities in NetScaler ADC and NetScaler Gateway on June 30, 2026, the most urgent being CVE-2026-8451 (CVSS 8.8), a pre-authentication out-of-bounds read in NetScaler’s XML/SAML parser that can leak fragments of appliance memory via the NSC_TASS cookie when a device is configured as a SAML Identity Provider.
Researchers classified it in the same “CitrixBleed” vulnerability family as the original CVE-2023-4966, CitrixBleed 2 (CVE-2025-5777), and CitrixBleed 3 (CVE-2026-3055), all of which were weaponized by ransomware actors following disclosure.
Exploitation attempts began less than 24 hours after disclosure. Security firm Lupovis observed threat actors probing exposed NetScaler systems with malformed <samlp:AuthnRequest> payloads padded with hundreds of spaces, a pattern matching watchTowr’s published detection artifact, with one campaign traced to IP 146.70.139[.]154.
Unlike earlier CitrixBleed variants that leaked kilobytes of memory including session tokens, CVE-2026-8451 leaks only small memory fragments per request and has not been confirmed to expose credentials or session IDs directly, though repeated requests could still expose process memory pointers useful for follow-on exploitation.
This flaw follows closely on the heels of CVE-2026-3055 (CVSS 9.3), a related NetScaler memory-overread bug patched in March 2026 that saw active reconnaissance within days and confirmed exploitation by March 30, 2026.
Affected products: NetScaler ADC/Gateway 14.1 before 14.1-72.61, 13.1 before 13.1-63.18, and the FIPS/NDcPP variants, when configured as a SAML Identity Provider. Secure Private Access Hybrid deployments using affected instances are also vulnerable.
Remediation:
/saml/login traffic and anomalous NSC_TASS cookie values for signs of probing| Vendor / Product | CVE | CVSS | Vulnerability Type | Disclosed | Confirmed Ransomware Link |
|---|---|---|---|---|---|
| Palo Alto GlobalProtect | CVE-2026-0257 | 7.8 (revised from 4.7) | Authentication bypass via cookie forgery | May 13, 2026 | Qilin affiliates |
| Fortinet FortiGate | Fortibleed (config/credential exposure) | N/A (mass credential exposure) | Credential harvesting from exposed configs | June 2026 | Not formally attributed |
| Check Point VPN | CVE-2026-50751 | 9.3 | Authentication bypass via IKEv1 certificate-validation flaw | June 8, 2026 | Qilin affiliate confirmed |
| Citrix NetScaler | CVE-2026-8451 | 8.8 | CitrixBleed-style memory overread (SAML XML parser) | June 30, 2026 | Not yet confirmed, high risk based on prior CitrixBleed pattern |
| Tool / Technique | Purpose | Associated Activity |
|---|---|---|
| Impacket | Post-exploitation lateral movement and protocol abuse | Palo Alto GlobalProtect intrusions |
| NTLM relay attacks | Credential relay for privilege escalation | Palo Alto GlobalProtect intrusions |
| Mimikatz | OS credential dumping (memory-resident credentials) | Qilin ransomware post-access activity |
| PsExec, RDP, WMI | Living-off-the-land lateral movement | Qilin ransomware operations |
| Custom Chrome credential-harvesting script (GPO-distributed) | Browser-stored credential theft domain-wide | Qilin ransomware |
| Windows Subsystem for Linux (WSL) abuse | EDR evasion during payload execution | Qilin ransomware (documented October 2025) |
| Custom VPNExtFeatures Vendor ID payload | IKEv1 authentication-flag manipulation | Check Point CVE-2026-50751 exploitation |
| Forged authentication override cookies | Session establishment without credentials/MFA | Palo Alto GlobalProtect CVE-2026-0257] |
| Malformed samlp:AuthnRequest payloads | Memory overread trigger | Citrix NetScaler CVE-2026-8451 |
| FortiGate configuration-file scraping and hash cracking | Mass credential extraction | Fortibleed campaign |
Analysis of confirmed ransomware activity tied to these VPN exploitation chains particularly Qilin, which is directly linked to the Check Point and Palo Alto flaws shows consistent sectoral targeting:
Geographically, victims concentrate in the United States, United Kingdom, Australia, and Western Europe high-GDP markets with greater ransom-payment capacity and stronger data-protection regulatory exposure.
| CVE | Vendor / Product | Type | CVSS | Key Precondition |
|---|---|---|---|---|
| CVE-2026-0257 | Palo Alto PAN-OS GlobalProtect | Authentication bypass (cookie forgery) | 7.8 | Auth override cookies enabled with reused certificate |
| CVE-2026-50751 | Check Point Remote Access/Mobile VPN | Authentication bypass (IKEv1 logic flaw) | 9.3 | IKEv1 enabled, no machine certificate required |
| CVE-2026-50752 | Check Point IKEv1 site-to-site VPN | Certificate validation flaw (AitM risk) | 7.4 | IKEv1 site-to-site configuration |
| CVE-2026-8451 | Citrix NetScaler ADC/Gateway | Memory overread (CitrixBleed-style) | 8.8 | Appliance configured as SAML IdP |
| CVE-2026-3055 | Citrix NetScaler ADC/Gateway | Memory overread (CitrixBleed 3) | 9.3 | Appliance configured as SAML IdP |
| N/A (Fortibleed) | Fortinet FortiGate | Configuration/credential exposure | N/A | Internet-exposed management interface, weak password hashing |
| Type | Value | Context |
|---|---|---|
| IP Address | 104.207.144[.]154 | Early exploitation source |
| IP Address | 146.19.216[.]119 | Exploitation activity |
| IP Address | 146.19.216[.]120 | Exploitation activity |
| IP Address | 146.19.216[.]125 | Exploitation activity |
| IP Address | 209.99.191[.]137 | Exploitation source |
| IP Address | 79.130.26[.]202 | Associated with host “Jocker” |
| IP Address | 146.70.165[.]52 | Exploitation source |
| IP Address | 216.238.74[.]98 | Authenticated as admin via GlobalProtect |
| IP Address | 64.190.113[.]151 | Successful admin login |
| Hostname | kali | Kali Linux client identifier; strong malicious signal |
| MAC Address | aa:bb:cc:dd:ee:ff | Trivially spoofed MAC used across campaigns |
| Type | Value | Context |
|---|---|---|
| IP Address | 146.70.139[.]154 | Linked exploitation campaign source |
| Payload pattern | Malformed <samlp:AuthnRequest> padded with hundreds of spaces | Matches watchTowr’s published detection artefact |
| Cookie anomaly | Anomalous NSC_TASS cookie values | Indicates memory-overread exploitation attempt |
| Endpoint | /saml/login | Primary attack surface for exploitation attempts |
| Type | Value | Context |
|---|---|---|
| Authentication anomaly | VPN session established without valid password submission | Core exploitation signature |
| Protocol flag | Manipulated authentication flags via VPNExtFeatures Vendor ID payload during IKEv1 negotiation | Confirmed exploitation technique |
| Timeline indicator | Exploitation activity beginning May 7, 2026, preceding public disclosure by one month | Indicates pre-disclosure targeting |
| Type | Value | Context |
|---|---|---|
| Exposure scale | ~75,000 FortiGate devices; 194 countries; 21,000+ domains | Confirmed compromised credential dataset |
| Behavioral indicator | Unexpected admin logins, new/unknown accounts, unexplained configuration changes | Sign of post-compromise activity |
| Hash indicator | Non-PBKDF2 (legacy) password hash encoding on admin accounts | Indicates unmitigated exposure to credential cracking |
| Type | Value | Context |
|---|---|---|
| IP Address | 31.41.244[.]100 | Associated with Qilin C2 and leak-site operations |
| Artifact | Randomized ransomware executable filenames in temp/user-accessible directories | Payload staging behavior |
| Artifact | Custom-extension encrypted files (extension varies per affiliate campaign) | Post-encryption indicator |
| Artifact | GPO-distributed Chrome credential-harvesting script | Domain-wide credential theft mechanism |
| Infrastructure | Qilin leak site (“Qilin blog”) on Tor (.onion) | Double-extortion publication platform |
| Tactic | Technique ID | Technique Name | Observed Context |
|---|---|---|---|
| Initial Access | T1078 | Valid Accounts | VPN credential abuse (Fortibleed, Check Point, GlobalProtect) |
| Initial Access | T1566 | Phishing | Secondary access vector for high-privilege targets |
| Initial Access | T1190 | Exploit Public-Facing Application | CVE-2026-0257, CVE-2026-50751, CVE-2026-8451 exploitation |
| Execution | T1059 | Command and Scripting Interpreter | Post-access scripting activity |
| Execution | T1072 | Software Deployment Tools | GPO-based script execution |
| Credential Access | T1003 | OS Credential Dumping | Mimikatz usage |
| Credential Access | T1555.003 | Credentials from Web Browsers | Chrome credential theft |
| Defense Evasion | T1562 | Impair Defenses | Safe-mode reboot, WSL abuse |
| Defense Evasion | T1036 | Masquerading | Spoofed MAC addresses, forged sessions |
| Lateral Movement | T1021 | Remote Services | RDP, WMI, PsExec, Impacket, NTLM relay |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | Pre-encryption data staging |
| Impact | T1486 | Data Encrypted for Impact | Ransomware deployment |
| Impact | T1490 | Inhibit System Recovery | Backup/recovery sabotage |
Organizations running any of the four affected products should prioritize the following actions, ranked by urgency:
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…