Improper Certificate Validation in Palo Alto Networks, Inc. products - CVE-2026-0296
Published: August 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to intercept and modify application communications.
The vulnerability exists due to improper certificate validation in the GlobalProtect App for Linux when establishing application communications over an adjacent network. A remote attacker can perform a man-in-the-middle attack to intercept and modify application communications.
VPN tunnel traffic is not impacted.
Affected software
GlobalProtect App for macOS
GlobalProtect App for Linux
How to mitigate CVE-2026-0296
GlobalProtect App for macOS - addressed in versions 6.0.15, 6.2.8-h13, 6.3.3-h14
GlobalProtect App for Linux - addressed in versions 6.0.15, 6.3.3-h15