GlobalProtect Improper Certificate Validation Enables Unauth MitM Attack
CVE-2026-0296 Published on August 13, 2026
GlobalProtect App: Improper Certificate Validation Bypass Vulnerability
Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted.
The GlobalProtect app on iOS, Android, and Chrome OS is not affected.
Vulnerability Analysis
Timeline
Initial Publication.
Weakness Type
Improper Certificate Validation
The software does not validate, or incorrectly validates, a certificate. When a certificate is invalid or malicious, it might allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. The software might connect to a malicious host while believing it is a trusted host, or the software might be deceived into accepting spoofed data that appears to originate from a trusted host.
Products Associated with CVE-2026-0296
Want to know whenever a new CVE is published for Palo Alto Networks Globalprotect App? stack.watch will email you.
Affected Versions
Palo Alto Networks GlobalProtect App:- Version 6.3.0 and below 6.3.3-h15 is affected.
- Version 6.2.0 is affected.
- Version 6.0.0 and below 6.0.15 is affected.
- Version 6.3.0 and below 6.3.3-h14 is affected.
- Version 6.2.0 and below 6.2.8-h13 is affected.
- Version 6.0.0 and below 6.0.15 is affected.
- Version All is unaffected.