Improper Certificate Validation in Palo Alto Networks, Inc. products - CVE-2026-0296

 

Improper Certificate Validation in Palo Alto Networks, Inc. products - CVE-2026-0296

Published: August 16, 2026


Vulnerability identifier: #VU143209
CSH Severity: Medium
CVSS v4: 8.4 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-0296
CWE-ID: CWE-295
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to intercept and modify application communications.

The vulnerability exists due to improper certificate validation in the GlobalProtect App for Linux when establishing application communications over an adjacent network. A remote attacker can perform a man-in-the-middle attack to intercept and modify application communications.

VPN tunnel traffic is not impacted.


Affected software

GlobalProtect app for Windows
GlobalProtect App for macOS
GlobalProtect App for Linux

How to mitigate CVE-2026-0296

Install security update from vendor's website.

GlobalProtect app for Windows - addressed in versions 6.0.15, 6.2.8-h13, 6.3.3-h14
GlobalProtect App for macOS - addressed in versions 6.0.15, 6.2.8-h13, 6.3.3-h14
GlobalProtect App for Linux - addressed in versions 6.0.15, 6.3.3-h15

External References

Related Security Bulletins