CVE-2026-0296: Improper certificate validation vulnerabilities in Palo
Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted. The GlobalProtect app on iOS, Android, and Chrome OS is not affected.
- EPSS 0.1% (0.6% percentile)
- CVSS 4.5 medium