CVE-2026-0297: GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake (Severity: MEDIUM)

Published Aug 12, 2026
·
Updated

A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated privileges (SYSTEM privileges on Windows, and root privileges on macOS and Linux).

Affected Software

10 affected componentsFixes available
All of the following
Palo Alto Networks GlobalProtect App=6.3.0, =6.2.0, =6.0.0
6.3.3-h156.0.15
Linux Linux*
All of the following
Palo Alto Networks GlobalProtect App=6.3.0, =6.2.0, =6.0.0
6.3.3-h146.2.8-h136.0.15
Apple macOS*
All of the following
Palo Alto Networks GlobalProtect App=6.3.0, =6.2.0, =6.0.0
6.3.3-h146.2.8-h136.0.15
Microsoft Windows*
All of the following
Palo Alto Networks GlobalProtect App=6.3.0, =6.0.0
6.3.56.0.15
Apple iOS*
All of the following
Palo Alto Networks GlobalProtect App=6.3.0, =6.0.0
6.3.56.0.15
Google Android*

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 6.3.3-h15Fixed in 6.0.15
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 6.3.3-h14Fixed in 6.2.8-h13Fixed in 6.0.15
  3. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 6.3.5Fixed in 6.0.15
  4. Upgrade

    Upgrade GlobalProtect App 6.0 to a version that resolves this vulnerability.

    Fixed in 6.0.15 or later
  5. Upgrade

    Upgrade GlobalProtect App 6.0 on ChromeOS to a version that resolves this vulnerability.

    Fixed in 6.0.15 or later
  6. Upgrade

    Upgrade GlobalProtect App 6.0 on Linux to a version that resolves this vulnerability.

    Fixed in 6.0.15 or later
  7. Upgrade

    Upgrade GlobalProtect App 6.0 on Windows to a version that resolves this vulnerability.

    Fixed in 6.0.15 or later
  8. Upgrade

    Upgrade GlobalProtect App 6.0 on iOS to a version that resolves this vulnerability.

    Fixed in 6.0.15 or later
  9. Upgrade

    Upgrade GlobalProtect App 6.0 on macOS to a version that resolves this vulnerability.

    Fixed in 6.0.15 or later
  10. Upgrade

    Upgrade GlobalProtect App 6.2 on Windows to a version that resolves this vulnerability.

    Fixed in 6.2.8-h13 (6.2.8-1045) or later
  11. Upgrade

    Upgrade GlobalProtect App 6.2 on macOS to a version that resolves this vulnerability.

    Fixed in 6.2.8-h13 (6.2.8-1045) or later
  12. Upgrade

    Upgrade GlobalProtect App 6.3 on Windows to a version that resolves this vulnerability.

    Fixed in 6.3.3-h14 (6.3.3-1121) or later
  13. Upgrade

    Upgrade GlobalProtect App 6.3 on macOS to a version that resolves this vulnerability.

    Fixed in 6.3.3-h14 (6.3.3-1121) or later
  14. Upgrade

    Upgrade GlobalProtect App 6.3/6.1 on Android to a version that resolves this vulnerability.

    Fixed in 6.3.5 or later
  15. Upgrade

    Upgrade GlobalProtect App 6.3/6.1 on ChromeOS to a version that resolves this vulnerability.

    Fixed in 6.3.5 or later
  16. Upgrade

    Upgrade GlobalProtect App 6.3/6.1 on iOS to a version that resolves this vulnerability.

    Fixed in 6.3.5 or later
  17. Upgrade

    Upgrade GlobalProtect App 6.3/6.2 on Linux to a version that resolves this vulnerability.

    Fixed in 6.3.3-h15 or later
  18. Configuration

    Modify GlobalProtect Portal configurations to disable IPSec/UDP tunneling by configuring 'Advanced Control for Tunnel Mode Behavior' so clients connect exclusively via SSL VPN mode.

    GlobalProtect Portal Advanced Control for Tunnel Mode Behavior = Enable SSL-Only VPN Connections (disable IPSec/UDP tunneling)
  19. Configuration

    On the GlobalProtect gateway, go to Network > Gateway > Agent > Tunnel Setting and un-check 'Enable IPSec' to configure an SSL-only tunnel protocol (disables IPSec/UDP tunneling).

    GlobalProtect gateway Enable IPSec = unchecked/disabled
  20. Configuration

    Ensure a 'Settings' section exists within the GlobalProtect section, then create /opt/paloaltonetworks/globalprotect/pangps.xml with the pre-deployment configuration key full-chain-cert-verify set to 'yes'.

    GlobalProtect (pangps.xml) Settings.full-chain-cert-verify = yes
  21. Configuration

    Use Xcode to edit /Library/Preferences/com.paloaltonetworks.GlobalProtect.settings.plist; within the 'Settings' section add the key 'full-chain-cert-verify' and set its string value to 'yes'.

    GlobalProtect app on macOS (com.paloaltonetworks.GlobalProtect.settings.plist) Settings.full-chain-cert-verify = yes
  22. Configuration

    For GlobalProtect 6.2.8 and GlobalProtect app 6.3.3 on Windows and macOS, enable the new configuration 'Enable Strict Certificate Check' to require certificate checks required to mitigate this issue on these platforms.

    GlobalProtect app (Windows and macOS) Enable Strict Certificate Check = enabled
  23. Compensating control

    Take the pre-deployment/portal/gateway configuration steps so clients connect using SSL-only (disable IPSec/UDP tunneling) to mitigate the risk of the UDP tunnel handshake buffer overflow.

  24. Operational

    Restart macOS after setting full-chain-cert-verify='yes'.

Event History

Aug 12, 2026
Advisory Published
via Palo Alto Networks·04:00 PM
Data Sourced
via Palo Alto Networks·04:00 PM
RemedyDescriptionSeverityWeaknessAffected Software
Aug 13, 2026
CVE Published
via MITRE·02:01 AM
Data Sourced
via MITRE·02:01 AM
DescriptionWeakness
Data Sourced
via NVD·03:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-0297?

The severity of CVE-2026-0297 is rated as high with a score of 7.7.

2

How do I fix CVE-2026-0297?

To fix CVE-2026-0297, update the Palo Alto Networks GlobalProtect app to the latest version that addresses the buffer overflow vulnerability.

3

What systems are affected by CVE-2026-0297?

CVE-2026-0297 affects the Palo Alto Networks GlobalProtect app running on Windows and macOS systems.

4

What type of vulnerability is CVE-2026-0297?

CVE-2026-0297 is a buffer overflow vulnerability that can allow for arbitrary code execution.

5

What are the potential impacts of CVE-2026-0297?

The potential impacts of CVE-2026-0297 include system disruption and escalation of privileges to SYSTEM on Windows or root on macOS.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203