CVE-2026-0295: A race condition in the Palo Alto Networks GlobalProtect™
A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root. The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected.
- EPSS 0.1% (0.3% percentile)
- CVSS 4.1 medium