Palo Alto Networks Globalprotect App
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Palo Alto Networks Globalprotect App.
By the Year
In 2026 there have been 9 vulnerabilities in Palo Alto Networks Globalprotect App with an average score of 5.0 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 9 | 4.98 |
It may take a day or so for new Globalprotect App vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Palo Alto Networks Globalprotect App Security Vulnerabilities
Priv Esc in Palo Alto GlobalProtect App on Desktop OS
CVE-2026-0299
5.9 - Medium
- August 13, 2026
Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges. The GlobalProtect app on iOS, Android, and Chrome OS is not affected.
Untrusted Path
Windows PLAP Improper Input Validation in Palo Alto GlobalProtect RCE via MitM
CVE-2026-0298
5.2 - Medium
- August 13, 2026
An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client. The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.
Code Injection
GlobalProtect Buffer Overflow Enables MitM Priv Esc
CVE-2026-0297
5.2 - Medium
- August 13, 2026
A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated privileges (SYSTEM privileges on Windows, and root privileges on macOS and Linux).
Memory Corruption
GlobalProtect Improper Certificate Validation Enables Unauth MitM Attack
CVE-2026-0296
4.5 - Medium
- August 13, 2026
Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted. The GlobalProtect app on iOS, Android, and Chrome OS is not affected.
Improper Certificate Validation
Local Privilege Escalation in Palo Alto GlobalProtect Client (macOS)
CVE-2026-0295
4.1 - Medium
- August 13, 2026
A race condition in the Palo Alto Networks GlobalProtect client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root. The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected.
Race Condition
GlobalProtect macOS Passcode Disclosure Vulnerability
CVE-2026-0267
- June 10, 2026
An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After the passcode is known, the user can perform these actions even if the GlobalProtect app configuration would not normally permit them to do so.
Insertion of Sensitive Information into Log File
GlobalProtect CVE-2026-0249 Improper Cert Validation Traffic Intercept
CVE-2026-0249
- May 13, 2026
Multiple improper certificate validation vulnerabilities in the Palo Alto Networks GlobalProtect app enables an attacker to intercept encrypted communications and potentially compromise the endpoint. This can enable a local non-administrative operating system user or an attacker on the same subnet to redirect traffic to an unauthorized server and facilitate the installation of malicious software. The GlobalProtect app on Linux, Windows, iOS and GlobalProtect UWP app are not affected.
Improper Certificate Validation
Buffer Overflow in Palo Alto GlobalProtect Enables Code Exec (CVE-2026-0250)
CVE-2026-0250
- May 13, 2026
A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect app that enables a man in the middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges. This vulnerability is triggered during the processing of requests and responses exchanged between Portal and Gateway. The GlobalProtect app on iOS is not affected.
Memory Corruption
Palo Alto GlobalProtect Local Priv Escal to SYSTEM/ROOT
CVE-2026-0251
- May 13, 2026
Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect app allow a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges. The GlobalProtect app on iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.
Untrusted Path
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Palo Alto Networks Globalprotect App or by Palo Alto Networks? Click the Watch button to subscribe.