CVE-2026-0296

Summary

Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted.

The GlobalProtect app on iOS, Android, and Chrome OS is not affected.

Affected Software

VendorProductVersion RangeStatus
Palo Alto NetworksGlobalProtect App6.3.0 < 6.3.3-h15affected
Palo Alto NetworksGlobalProtect App6.2.0affected
Palo Alto NetworksGlobalProtect App6.0.0 < 6.0.15affected
Palo Alto NetworksGlobalProtect App6.3.0 < 6.3.3-h14affected
Palo Alto NetworksGlobalProtect App6.2.0 < 6.2.8-h13affected
Palo Alto NetworksGlobalProtect App6.0.0 < 6.0.15affected
Palo Alto NetworksGlobalProtect AppAllunaffected

Weaknesses

  • CWE-295: CWE-295 Improper Certificate Validation

Workarounds

No known workarounds or mitigations exist for this issue.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References