Palo Alto Networks has patched six vulnerabilities across its GlobalProtect VPN client and PAN-OS firewall software, and the two that matter most let an attacker sitting between a laptop and its VPN gateway run code with the highest privileges on that machine.
The company published its advisories on August 12, and Hong Kong's HKCERT restated them for regional defenders in a security bulletin on August 14. Palo Alto says it is not aware of any malicious exploitation of any of the six.
What's affected
Five of the six sit in the GlobalProtect app, the client software staff run on laptops and phones to reach the corporate network. The sixth is in PAN-OS, the operating system on Palo Alto's firewalls.
- GlobalProtect App 6.0 before 6.0.15 on Android, Chrome OS, iOS, Linux, macOS and Windows
- GlobalProtect App 6.2 before 6.2.8-h13 (6.2.8-1045) on Windows and macOS, and every 6.2 release on Linux
- GlobalProtect App 6.3 before 6.3.5 on Android, Chrome OS and iOS, before 6.3.3-h15 on Linux, and before 6.3.3-h14 (6.3.3-1121) on Windows and macOS
- PAN-OS 10.2 before 10.2.8 and PAN-OS 11.1 before 11.1.16-h1, Prisma Access 10.2 before 10.2.10, and Cloud NGFW on AWS and Azure
How the attacks work
The most serious pair need a man in the middle, meaning someone who can intercept and tamper with the client's traffic, on a hostile Wi-Fi network for example, or who can pose as a rogue VPN gateway. CVE-2026-0297 is a buffer overflow in the app's UDP tunnel handshake that Palo Alto says can disrupt system processes and potentially execute arbitrary code with elevated privileges, SYSTEM on Windows and root on macOS and Linux. CVE-2026-0298 is an improper input validation flaw in the Windows Pre-Logon Access Provider, the component that brings the VPN up before a user has even signed in, and it lets the same kind of attacker execute code as SYSTEM.
Two others are local privilege escalations, useful to someone who already has a foothold on the machine. CVE-2026-0299 is an untrusted search path issue that takes an ordinary user to SYSTEM on Windows and root on macOS and Linux, and CVE-2026-0295 is a race condition that reaches root on macOS only. CVE-2026-0296 is an improper certificate validation bug that lets a man in the middle intercept and modify the app's communications, though Palo Alto notes VPN tunnel traffic itself is not affected. The lone PAN-OS issue, CVE-2026-0301, leaks sensitive information from the URL Filtering feature to an unauthenticated user with network access, and does not affect Panorama.
How serious is it
Palo Alto rates five of the six medium and the PAN-OS leak low, its own scores run from 1.7 to 5.9, and it marks exploit maturity for all of them as unreported. None of these is a remote, unauthenticated takeover of a firewall, which is worth saying plainly, because Palo Alto's edge products have been on the receiving end of exactly that. In June we covered active exploitation of a GlobalProtect authentication bypass, and attackers keep returning to VPN entry points, as they did in the Cisco firewall crashes reported this month.
What you should do
Update the client fleet first, since five of the six flaws live there and the client is the part that travels onto untrusted networks. Palo Alto's guidance is to move GlobalProtect on Windows and macOS to 6.3.3-h14 (6.3.3-1121) or 6.2.8-h13, Linux users on 6.2 and 6.3 to 6.3.3-h15, and anyone still on 6.0 to 6.0.15. Firewall administrators should take PAN-OS 10.2.8 or 11.1.16-h1, and Cloud NGFW customers can arrange an on demand upgrade through Palo Alto support. Per issue detail sits in the vendor's own advisories, starting with the UDP tunnel handshake overflow and the privilege escalation set.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.