← All Advisories

CVE-2026-0296

Status: UPDATED  |  Advisory ID: CVE-2026-0296

Key Details

CVECVE-2026-0296
CVSSCVSS 7.4 (High): attack vector is network; attack complexity is high; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is none. (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)
Affected productsPalo Alto Networks GlobalProtect
Exploitation statusPalo Alto Networks is not aware of any malicious exploitation of this issue.

What to Know

Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted.

The GlobalProtect app on iOS, Android, and Chrome OS is not affected.

What to Do

GlobalProtect App: upgrade paths vary by platform/version (see the advisory's own version table); iOS, Android, and Chrome OS are not affected. No known workarounds beyond upgrading to a fixed release.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-0296
Vendor advisoryhttps://security.paloaltonetworks.com/CVE-2026-0296