CVE-2026-0296
Received Received - Intake

Improper Certificate Validation in Palo Alto Networks GlobalProtect App

Vulnerability report for CVE-2026-0296, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: Palo Alto Networks, Inc.

Description

Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted. The GlobalProtect app on iOS, Android, and Chrome OS is not affected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-13
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
palo_alto_networks globalprotect to 6.3.3-h15 (exc)
palo_alto_networks globalprotect to 6.2.8-h13 (exc)
palo_alto_networks globalprotect to 6.0.15 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-295 The product does not validate, or incorrectly validates, a certificate.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-0296 is a vulnerability in Palo Alto Networks' GlobalProtect app where improper certificate validation allows an unauthenticated attacker with man-in-the-middle access to intercept and modify application communications. This does not affect VPN tunnel traffic.

Detection Guidance

Detecting this vulnerability requires checking the installed version of the GlobalProtect app against the affected versions. On Linux, run: globalprotect version. On macOS or Windows, check the app version via the GUI or package manager. Compare the output against versions prior to 6.3.3-h15 (Linux), 6.3.3-h14 (macOS/Windows), 6.2.8-h13 (macOS/Windows), or 6.0.15 (all platforms).

Monitor network traffic for unusual certificate validation failures or MitM attempts. Use tools like Wireshark to inspect TLS handshakes for the GlobalProtect app. Ensure no downgraded or self-signed certificates are accepted by the app.

Impact Analysis

An attacker could intercept sensitive data transmitted by the GlobalProtect app, modify communications, or potentially gain unauthorized access to application data. This risk applies to users on Linux, macOS, and Windows platforms.

Compliance Impact

This vulnerability could lead to unauthorized access or exposure of sensitive data, potentially violating compliance requirements for data protection such as GDPR or HIPAA. Organizations using affected versions should upgrade to mitigate risks.

Mitigation Strategies

Upgrade the GlobalProtect app to the latest patched versions: 6.3.3-h15 or later for Linux, 6.3.3-h14 or later for macOS and Windows, 6.2.8-h13 or later for macOS and Windows, and 6.0.15 or later for all platforms.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-0296. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart