CVE-2026-0295: A race condition in the Palo Alto Networks GlobalProtect™

A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root. The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected.

Related briefings

Browse the CVE database

Read the full analysis on IntelFusions