Skip to content
Palo Alto NetworksCVE-2026-0297

Palo Alto Networks GlobalProtect App: buffer overflow

Medium5.2CVE-2026-0297 · Published Aug 13, 2026 · updated Sep 10, 2026

A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated privileges (SYSTEM privileges on Windows, and root privileges on macOS and Linux).

Palo Alto Networks advisory

Affected versions

PackageAffectedFixed in
GlobalProtect App
Product
>= 6.3.0, < 6.3.3-h156.3.3-h15
<= 6.2.0No fix yet
>= 6.0.0, < 6.0.156.0.15
>= 6.3.0, < 6.3.3-h146.3.3-h14
>= 6.2.0, < 6.2.8-h136.2.8-h13
>= 6.0.0, < 6.0.156.0.15
>= 6.3.0, < 6.3.56.3.5
>= 6.0.0, < 6.0.156.0.15
Details and references
CVSS 4.0
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-787

More Palo Alto Networks advisories

All Palo Alto Networks
Advisory
Palo Alto Networks Cloud NGFW: information disclosure
Low1.7Aug 13
Palo Alto Networks GlobalProtect App: improper input validation
Medium5.2Aug 13
Palo Alto Networks GlobalProtect App: privilege escalation
Medium5.9Aug 13
Palo Alto Networks Prisma: local attacker could bypass the anti-tamper...
Medium5.6Aug 13
Palo Alto Networks Prisma Access Agent: privilege escalation
Medium6.0Aug 13
Palo Alto Networks GlobalProtect App: race condition
Medium4.1Aug 13

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.