Security Advisory Desk
mediumQCS priority 76/100Palo Alto Networks

CVE-2026-0250 GlobalProtect App: Buffer Overflow Vulnerability during connection to Portal or Gateway (Severity: MEDIUM)

A security vulnerability affecting Palo Alto Networks' GlobalProtect app could allow attackers to disrupt the system or execute malicious code with high-level system rights when the app connects to its portal or gateway. This issue affects most operating systems except iOS. Users should update their app to fixed versions to protect their systems.

Published 12/9/2026, 12:30:00 amVerified 15/9/2026, 5:08:29 amRevision 1
Palo Alto Networks medium network security advisory visual

In plain language

What this advisory means

A security vulnerability affecting Palo Alto Networks' GlobalProtect app could allow attackers to disrupt the system or execute malicious code with high-level system rights when the app connects to its portal or gateway. This issue affects most operating systems except iOS. Users should update their app to fixed versions to protect their systems.

Technical explanation

How the issue affects the environment

The GlobalProtect app suffers a buffer overflow vulnerability triggered during processing of requests and responses between the Portal and Gateway. This enables a man-in-the-middle attacker to write beyond allocated memory bounds (CWE-787), potentially disrupting processes or running arbitrary code with SYSTEM privileges. The flaw affects GlobalProtect versions on Windows, macOS, Linux, Android, and ChromeOS, excluding iOS.

Operational impact

Why teams should care

Exploiting this vulnerability could compromise the confidentiality, integrity, and availability of systems running the vulnerable GlobalProtect app. Attackers could disrupt service or gain system-level control, leading to significant business risks including data breaches and operational outages.

Immediate action

Organizations should upgrade GlobalProtect App installations to the specified fixed versions as soon as they become available to mitigate this vulnerability. No special configuration is needed to be exposed, so prompt updates are critical.

Affected and fixed releases

Affected versionsGlobalProtect App versions prior to 6.3.3-h9 on Windows and macOS, Versions prior to 6.3.5 on Android and ChromeOS, Versions prior to 6.3.3-h15 on Linux (expected 09/17), Versions prior to 6.0.15 on Linux (expected 10/29), Versions prior to 6.0.13 on Windows and macOS, Versions prior to 6.0.15 on Android and ChromeOS (expected 10/29), GlobalProtect UWP App versions prior to 6.3.3-h10 on Windows
Fixed versions6.3.3-h9 or later for Windows and macOS, 6.3.5 or later for Android and ChromeOS, 6.3.3-h15 or later for Linux, 6.0.15 or later for Linux, Android, and ChromeOS, 6.0.13 or later for Windows and macOS, 6.3.3-h10 or later for GlobalProtect UWP on Windows

Temporary risk reduction

No known workarounds exist for this vulnerability; applying the update is the only effective mitigation currently available.

Evidence and validation checklist

  • Vendor advisory from Palo Alto Networks
  • CVE listing for CVE-2026-0250
  • Product version affected and fixed listings included in advisory
  • Detailed technical description and impact assessment
  • Statements on exploitation status and absence of workarounds

Authoritative reference

Palo Alto Networks Security Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source
CVE-2026-0250 GlobalProtect App: Buffer Overflow | Advisory | QCS