CVE-2026-0297
GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake
Description
A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated privileges (SYSTEM privileges on Windows, and root privileges on macOS and Linux).
Weakness: CWE-787
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | GlobalProtect | VPN & Remote Access | cna-assigner |
Vendor-reported products (3)
- Palo Alto Networks · GlobalProtect App
- Palo Alto Networks · GlobalProtect App
- Palo Alto Networks · GlobalProtect App
Credit
our internal security research teams
Vendor remediation
VERSION MINOR VERSION SUGGESTED SOLUTION GlobalProtect App 6.3/6.2 on Linux 6.2.0 through 6.3.3-h14 Upgrade to 6.3.3-h15 or later. GlobalProtect App 6.0 on Linux 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later. GlobalProtect App 6.3 on macOS 6.3.0 through 6.3.3-h13 Upgrade to 6.3.3-h14 (6.3.3-1121) or later. GlobalProtect App 6.2 on macOS 6.2.0 through 6.2.8-h12 Upgrade to 6.2.8-h13 (6.2.8-1045) or later. GlobalProtect App 6.0 on macOS 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later. GlobalProtect App 6.3 on Windows 6.3.0 through 6.3.3-h13 Upgrade to 6.3.3-h14 (6.3.3-1121) or later. GlobalProtect App 6.2 on Windows 6.2.0 through 6.2.8-h12 Upgrade to 6.2.8-h13 (6.2.8-1045) or later. GlobalProtect App 6.0 on Windows 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later. GlobalProtect App 6.3/6.1 on iOS 6.1.0 through 6.3.4 Upgrade to 6.3.5 or later. GlobalProtect App 6.0 on iOS 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later. GlobalProtect App 6.3/6.1 on Android 6.1.0 through 6.3.4 Upgrade to 6.3.5 or later. GlobalProtect App 6.0 on Android 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later. GlobalProtect App 6.3/6.1 on ChromeOS 6.1.0 through 6.3.4 Upgrade to 6.3.5 or later. GlobalProtect App 6.0 on ChromeOS 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later.