GlobalProtect App: Improper Certificate Validation Bypass Vulnerability
Published Aug 13, 2026
4.5
MEDIUMCVSS 4.0
EPSS 0.14%
Description
Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted.
The GlobalProtect app on iOS, Android, and Chrome OS is not affected.
Affected products
-
- Version 6.0.0StatusaffectedConstraints<6.0.15
- Version 6.2.0StatusaffectedConstraints<6.2.8-h13
- Version 6.2.0StatusaffectedConstraints-
- Version 6.3.0StatusaffectedConstraints<6.3.3-h14
- Version 6.3.0StatusaffectedConstraints<6.3.3-h15
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Palo Alto Networks | GlobalProtect App | unaffected |
|
- ≥ 6.0.0 · < 6.0.15
- ≥ 6.0.0 · < 6.0.15
- ≥ 6.0.0 · < 6.0.15
- ≥ 6.2.0 · < 6.2.8
- ≥ 6.2.0 · < 6.2.8
- ≥ 6.2.0 · ≤ 6.2.9
- ≥ 6.3.0 · < 6.3.3
- n/a
- 6.2.8
- 6.2.8
- 6.2.8
- 6.2.8
- 6.2.8
- 6.2.8
- 6.2.8
- 6.2.8
- 6.2.8
- 6.2.8
- 6.2.8
- 6.2.8
- 6.2.8
- 6.3.3
- 6.3.3
- 6.3.3
- 6.3.3
- 6.3.3
- 6.3.3
- 6.3.3
- 6.3.3
- 6.3.3
- 6.3.3
- 6.3.3
- 6.3.3
- 6.3.3
- 6.3.3
- 6.3.3
- 6.3.3
- 6.3.3
- 6.3.3
- 6.3.3
- 6.3.3
- 6.3.3
- 6.3.3
- 6.3.3
- 6.3.3
- 6.3.3
- 6.3.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
VERSION MINOR VERSION SUGGESTED SOLUTION GlobalProtect App 6.3/6.2 on Linux 6.2.0 through 6.3.3-h14 Upgrade to 6.3.3-h15 or later. GlobalProtect App 6.0 on Linux 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later. GlobalProtect App 6.3 on macOS 6.3.0 through 6.3.3-h13 Upgrade to 6.3.3-h14 (6.3.3-1121) or later. GlobalProtect App 6.2 on macOS 6.2.0 through 6.2.8-h12 Upgrade to 6.2.8-h13 (6.2.8-1045) or later. GlobalProtect App 6.0 on macOS 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later. GlobalProtect App 6.3 on Windows 6.3.0 through 6.3.3-h13 Upgrade to 6.3.3-h14 (6.3.3-1121) or later. GlobalProtect App 6.2 on Windows 6.2.0 through 6.2.8-h12 Upgrade to 6.2.8-h13 (6.2.8-1045) or later. GlobalProtect App 6.0 on Windows 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later. GlobalProtect App on iOS No action needed. GlobalProtect App on Android No action needed. GlobalProtect App on Chrome OS No action needed.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-57710 Advisory
- https://security.paloaltonetworks.com/CVE-2026-0296 vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-57710 | Advisory | |
| https://security.paloaltonetworks.com/CVE-2026-0296 | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.