[NEW] [high] Palo Alto Networks GlobalProtect App: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in Palo Alto Networks GlobalProtect App to gain administrator privileges, execute arbitrary code with administrator privileges, bypass security measures, manipulate and disclose data as well as trigger a Denial-of-Service condition.
CSIRTS triage
- What
- Multiple vulnerabilities in GlobalProtect App allow attackers to gain administrator privileges, execute arbitrary code, bypass security measures, and cause denial of service.
- Who is affected
- GlobalProtect App deployments of unspecified versions are affected.
- Urgency
- High urgency; privilege escalation and code execution capabilities pose critical risk to endpoint security.
- Action
- Update GlobalProtect App to a version patching CVE-2026-0295 through CVE-2026-0299 immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch GlobalProtect App
Get an email when a new GlobalProtect App advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2804
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-02950.08% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 0% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-02960.09% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-02970.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-02980.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-02990.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-0295 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-0296 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-0297 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-0298 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-0299 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownPalo Alto Products Multiple Vulnerabilitieshkcert
- unknownCVE-2026-0299: Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable …nvd
- unknownCVE-2026-0298: An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLA…nvd
- unknownCVE-2026-0297: A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enable…nvd
- unknownCVE-2026-0296: Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable…nvd
- unknownCVE-2026-0295: A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally aut…nvd
- unknownMultiple vulnerabilities in Palo Alto Networks products (August 13, 2026)cert-fr-avis
- mediumCVE-2026-0298 GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP) (Sev…paloalto
- mediumCVE-2026-0297 GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake (Severity: MEDIUM)paloalto
- mediumCVE-2026-0295 GlobalProtect App: Local Privilege Escalation via Race Condition on macOS (Severity: MEDIUM)paloalto
- mediumCVE-2026-0299 GlobalProtect App: Local Privilege Escalation Vulnerabilities (Severity: MEDIUM)paloalto
- mediumCVE-2026-0296 GlobalProtect App: Improper Certificate Validation Bypass Vulnerability (Severity: MEDIUM)paloalto
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] GStreamer: Multiple Vulnerabilities2026-08-17
- high[NEW] [high] Golang Go: Multiple vulnerabilities2026-08-17
- medium[NEW] [medium] Apache Struts: Multiple vulnerabilities2026-08-17
- high[NEW] [high] PostgreSQL: Multiple vulnerabilities2026-08-17
- high[UPDATE] [high] Oracle PeopleSoft: Multiple Vulnerabilities2026-08-17