CVE-2026-0296
Received
Received - Intake
Improper Certificate Validation in Palo Alto Networks GlobalProtect App
Vulnerability report for CVE-2026-0296, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-13
Last updated on: 2026-08-13
Assigner: Palo Alto Networks, Inc.
Description
Description
Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted.
The GlobalProtect app on iOS, Android, and Chrome OS is not affected.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| palo_alto_networks | globalprotect | to 6.3.3-h15 (exc) |
| palo_alto_networks | globalprotect | to 6.2.8-h13 (exc) |
| palo_alto_networks | globalprotect | to 6.0.15 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-295 | The product does not validate, or incorrectly validates, a certificate. |