Skip to content
Multiple Vulnerabilities in Palo Alto Networks GlobalProtect App Disclosed

Multiple Vulnerabilities in Palo Alto Networks GlobalProtect App Disclosed

First seen 13 Aug 2026, 12:20 UTC •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 14, 2026 at 11:53 UTC
  • •Four critical vulnerabilities disclosed in Palo Alto Networks GlobalProtect app.
  • •Exploits could allow attackers to execute arbitrary code with elevated privileges.
  • •Users are advised to upgrade to the latest app versions to mitigate risks.

On August 14, 2026, Palo Alto Networks disclosed four critical vulnerabilities (CVE-2026-0296, CVE-2026-0297, CVE-2026-0298, CVE-2026-0299) in the GlobalProtect app affecting Windows, macOS, and Linux systems. These vulnerabilities include a buffer overflow, improper certificate validation, local privilege escalation, and improper input validation. Attackers could exploit these vulnerabilities to execute arbitrary code with elevated privileges, impacting system security. The vulnerabilities do not affect the GlobalProtect app on iOS, Android, or Chrome OS. Palo Alto Networks is not aware of any active exploitation of these issues. Users are advised to upgrade to the latest versions of the GlobalProtect app to mitigate risks. Specific versions affected include 6.0.0 through 6.3.3-h14 across various platforms. The CVSS scores range from 4.5 to 8.5, indicating varying levels of severity.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 51d ago How this analysis works

Timeline

2026-08-14
CVE-2026-0296 disclosed
Improper certificate validation vulnerability allows MitM attacks on GlobalProtect app.
security.paloaltonetworks.com
2026-08-14
CVE-2026-0297 disclosed
Buffer overflow vulnerability enables arbitrary code execution with elevated privileges.
security.paloaltonetworks.com
2026-08-14
CVE-2026-0298 disclosed
Improper input validation in Windows PLAP component allows code execution with SYSTEM privileges.
security.paloaltonetworks.com
2026-08-14
CVE-2026-0299 disclosed
Local privilege escalation vulnerability allows non-admin users to execute commands with elevated privileges.
security.paloaltonetworks.com

More articles in this cluster (5)