CVE-2026-0296: GlobalProtect App: Improper Certificate Validation Bypass Vulnerability (Severity: MEDIUM)
Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted.
The GlobalProtect app on iOS, Android, and Chrome OS is not affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.3-h15Fixed in 6.0.15 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.3-h14Fixed in 6.2.8-h13Fixed in 6.0.15 - Upgrade
Upgrade
GlobalProtect App (Linux) 6.0to a version that resolves this vulnerability.Fixed in 6.0.15 - Upgrade
Upgrade
GlobalProtect App (Windows) 6.0to a version that resolves this vulnerability.Fixed in 6.0.15 - Upgrade
Upgrade
GlobalProtect App (macOS) 6.0to a version that resolves this vulnerability.Fixed in 6.0.15 - Upgrade
Upgrade
GlobalProtect App (Windows) 6.2to a version that resolves this vulnerability.Fixed in 6.2.8-h13 (6.2.8-1045) - Upgrade
Upgrade
GlobalProtect App (macOS) 6.2to a version that resolves this vulnerability.Fixed in 6.2.8-h13 (6.2.8-1045) - Upgrade
Upgrade
GlobalProtect App (Windows) 6.3to a version that resolves this vulnerability.Fixed in 6.3.3-h14 (6.3.3-1121) - Upgrade
Upgrade
GlobalProtect App (macOS) 6.3to a version that resolves this vulnerability.Fixed in 6.3.3-h14 (6.3.3-1121) - Upgrade
Upgrade
GlobalProtect App (Linux) 6.2/6.3to a version that resolves this vulnerability.Fixed in 6.3.3-h15
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0296?
The severity of CVE-2026-0296 is high, rated at 7.4 on the CVSS scale.
How do I fix CVE-2026-0296?
To fix CVE-2026-0296, ensure that you update the Palo Alto Networks GlobalProtect App to the latest version provided by the vendor.
What type of vulnerability is CVE-2026-0296?
CVE-2026-0296 is classified as an improper certificate validation bypass vulnerability.
What impact does CVE-2026-0296 have on users?
CVE-2026-0296 allows unauthenticated attackers with man-in-the-middle access to intercept and modify communications within the GlobalProtect app.
Which platforms are affected by CVE-2026-0296?
CVE-2026-0296 affects the Palo Alto Networks GlobalProtect app on iOS, Android, and Chrome OS.