Multiple vulnerabilities in Palo Alto Networks GlobalProtect app

25 Aug 2026

Security researchers have discovered multiple vulnerabilities in the Palo Alto Networks GlobalProtect App. These include privilege escalation, code execution, certificate validation, and buffer overflow vulnerabilities.

 

Through this blog, we will understand what the flaws in the Palo Alto Networks GlobalProtect app are about, the threats posed by them, and what organizations can do to defend against them.

About the vulnerabilities

Vendor + component affected 

Potentially exposed platforms  

CVEs/CVSS Score/Type 

Palo Alto Networks + GlobalProtect App  

 

 

 

 

 

Windows, macOS, and Linux 

 

 

CVE-2026-0251/5.9(Medium)/Local Privilege Escalation 

CVE-2026-0296/4.5(Medium)/Improper Certificate Validation Bypass  

CVE-2026-0297/5.2(Medium)/Buffer Overflow  

CVE-2026-0298/5.2 (Medium)/Code Execution 

CVE-2026-0299/5.9 (Medium)/Local Privilege Escalation 

 

 

These flaws should be treated with high priority because GlobalProtect operates with elevated privileges while offering connectivity to enterprise environments.

What can attackers do with the vulnerabilities?

Vulnerability  

What an attacker can do? 

CVE-2026-0251 

 

  • Escalate local privileges to SYSTEM/root level 
  • Execute arbitrary commands with elevated privileges 
  • Modify system files and security settings 
  • Install malware or establish persistence on the endpoint  

CVE-2026-0296 

 

  • Intercept GlobalProtect application communications 
  • Modify communications through M-i-t-M attack 
  • Manipulate application traffic  
  • Influence how the application behaves 

CVE-2026-0297 

 

  • Trigger memory corruption in the affected GlobalProtect component  
  • Cause the app’s process to crash or become unavailable 
  • Execute arbitrary code with SYSTEM/root-level privileges 
  • Gain control over the affected endpoint 

CVE-2026-0298 

 

  • Execute arbitrary code through the GlobalProtect pre-logon component 
  • Execute malicious codes with SYSTEM-level privileges 
  • Cause a compromise of the affected Windows endpoint 
  • Modify system components 
  • Access sensitive data 
  • Install malware 

 

CVE-2026-0299 

 

  • Escalate local privileges to SYSTEM/root 
  • Execute arbitrary commands with elevated privileges 
  • Disable or tamper with security controls 
  • Install malware  
  • Establish mechanism for persistence access on endpoints 

Official security guidance

Organizations should:

 

  • Identify all endpoints running GlobalProtect 6.0, 6.2, or 6.3.
  • Upgrade GlobalProtect to the latest vendor-supported and fixed release.
  • Prioritize Windows endpoints because several vulnerabilities specifically affect the Windows client.
  • Restrict unnecessary local administrator privileges on GlobalProtect-enabled endpoints.
  • Review endpoint and Active Directory authentication logs for suspicious activity following potential exploitation.
  • Investigate unexpected SYSTEM/root-level process execution associated with GlobalProtect.
  • Ensure GlobalProtect clients are obtained only from trusted organizational deployment channels.

SharkStriker’s recommendations

  • Immediately inventory and upgrade vulnerable GlobalProtect clients to the latest fixed version provided by Palo Alto Networks.
  • Prioritize systems running GlobalProtect with local users who do not require administrative privileges.
  • Monitor for unexpected SYSTEM/root process execution and suspicious GlobalProtect-related activity.
  • Review Active Directory authentication activity for unusual logons or credential use from endpoints running vulnerable GlobalProtect versions.
  • Investigate and isolate affected endpoints where exploitation or suspicious privilege escalation is suspected.

SharkStriker’s actions

  • Threat intelligence validated.
  • Reviewed Palo Alto Networks security advisories and publicly available research.
  • Initiated customer exposure assessment.
  • Reviewed detection opportunities for privilege escalation and suspicious GlobalProtect activity.
  • Prepared advisories for the affected customers.

Get in Touch With us

We have explored what risk tolerance and risk appetite are and how important they are together in helping businesses align cybersecurity with their business goals. It can help CISOs, and C-suite make informed investment decisions for cybersecurity.

LEARN MORE