Multiple vulnerabilities in Palo Alto Networks GlobalProtect app
25 Aug 2026
Security researchers have discovered multiple vulnerabilities in the Palo Alto Networks GlobalProtect App. These include privilege escalation, code execution, certificate validation, and buffer overflow vulnerabilities.
Through this blog, we will understand what the flaws in the Palo Alto Networks GlobalProtect app are about, the threats posed by them, and what organizations can do to defend against them.
About the vulnerabilities
|
Vendor + component affected |
Potentially exposed platforms |
CVEs/CVSS Score/Type |
|
Palo Alto Networks + GlobalProtect App
|
Windows, macOS, and Linux
|
CVE-2026-0251/5.9(Medium)/Local Privilege Escalation CVE-2026-0296/4.5(Medium)/Improper Certificate Validation Bypass CVE-2026-0297/5.2(Medium)/Buffer Overflow CVE-2026-0298/5.2 (Medium)/Code Execution CVE-2026-0299/5.9 (Medium)/Local Privilege Escalation
|
These flaws should be treated with high priority because GlobalProtect operates with elevated privileges while offering connectivity to enterprise environments.
What can attackers do with the vulnerabilities?
|
Vulnerability |
What an attacker can do? |
|
CVE-2026-0251 |
|
|
CVE-2026-0296 |
|
|
CVE-2026-0297 |
|
|
CVE-2026-0298 |
|
|
CVE-2026-0299 |
|
Official security guidance
Organizations should:
- Identify all endpoints running GlobalProtect 6.0, 6.2, or 6.3.
- Upgrade GlobalProtect to the latest vendor-supported and fixed release.
- Prioritize Windows endpoints because several vulnerabilities specifically affect the Windows client.
- Restrict unnecessary local administrator privileges on GlobalProtect-enabled endpoints.
- Review endpoint and Active Directory authentication logs for suspicious activity following potential exploitation.
- Investigate unexpected SYSTEM/root-level process execution associated with GlobalProtect.
- Ensure GlobalProtect clients are obtained only from trusted organizational deployment channels.
SharkStriker’s recommendations
- Immediately inventory and upgrade vulnerable GlobalProtect clients to the latest fixed version provided by Palo Alto Networks.
- Prioritize systems running GlobalProtect with local users who do not require administrative privileges.
- Monitor for unexpected SYSTEM/root process execution and suspicious GlobalProtect-related activity.
- Review Active Directory authentication activity for unusual logons or credential use from endpoints running vulnerable GlobalProtect versions.
- Investigate and isolate affected endpoints where exploitation or suspicious privilege escalation is suspected.
SharkStriker’s actions
- Threat intelligence validated.
- Reviewed Palo Alto Networks security advisories and publicly available research.
- Initiated customer exposure assessment.
- Reviewed detection opportunities for privilege escalation and suspicious GlobalProtect activity.
- Prepared advisories for the affected customers.