Security Advisory Desk
mediumQCS priority 76/100Palo Alto Networks

CVE-2026-0296 GlobalProtect App: Improper Certificate Validation Bypass Vulnerability (Severity: MEDIUM)

A vulnerability in the Palo Alto Networks GlobalProtect app's certificate checking lets attackers intercept and alter communications on some computer systems. This weakness does not affect the iOS, Android, or Chrome OS versions, nor does it impact VPN tunnel traffic. Upgrading the app to the fixed versions eliminates the risk.

Published 12/9/2026, 12:30:00 amVerified 16/9/2026, 6:45:41 amRevision 2
Palo Alto Networks medium network security advisory visual

In plain language

What this advisory means

A vulnerability in the Palo Alto Networks GlobalProtect app's certificate checking lets attackers intercept and alter communications on some computer systems. This weakness does not affect the iOS, Android, or Chrome OS versions, nor does it impact VPN tunnel traffic. Upgrading the app to the fixed versions eliminates the risk.

Technical explanation

How the issue affects the environment

CVE-2026-0296 is an improper certificate validation vulnerability (CWE-295) in the GlobalProtect app on Linux, macOS, and Windows. It allows an unauthenticated attacker with man-in-the-middle access to bypass certificate validation, enabling interception and modification of application-layer communications. The VPN tunnel functionality is unaffected, and the mobile and Chrome OS apps are not impacted. No user privileges are needed, and no user interaction is required during the attack. The vulnerability affects all versions prior to patched releases from 6.0.15, 6.2.8-h13, and 6.3.3-h14, depending on platform and app version.

Operational impact

Why teams should care

This vulnerability could compromise the confidentiality and integrity of communications between the GlobalProtect app and its servers on affected platforms. Attackers with network proximity could intercept and modify data, potentially exposing sensitive information or injecting malicious content. However, VPN tunnel traffic remains protected, and mobile users are unaffected. Organizations should update promptly to avoid data interception risks in enterprise environments relying on GlobalProtect desktop clients.

Immediate action

Upgrade the GlobalProtect app on affected platforms to the minimum fixed versions provided by Palo Alto Networks, such as 6.3.3-h15 for Linux, 6.3.3-h14 for macOS and Windows, 6.2.8-h13 for macOS and Windows, and 6.0.15 for Linux, macOS, and Windows. No configuration changes are required beyond the upgrade.

Affected and fixed releases

Affected versionsGlobalProtect App versions prior to 6.3.3-h15 on Linux, GlobalProtect App versions prior to 6.3.3-h14 on macOS and Windows, GlobalProtect App versions prior to 6.2.8-h13 on macOS and Windows, GlobalProtect App versions prior to 6.0.15 on Linux, macOS, and Windows
Fixed versionsGlobalProtect App 6.3.3-h15 or later on Linux, GlobalProtect App 6.3.3-h14 or later on macOS and Windows, GlobalProtect App 6.2.8-h13 or later on macOS and Windows, GlobalProtect App 6.0.15 or later on Linux, macOS, and Windows

Temporary risk reduction

There are no known workarounds or mitigations available for this vulnerability. Users should apply the provided upgrades as soon as possible.

Evidence and validation checklist

  • Palo Alto Networks Security Advisories CVE-2026-0296
  • Description indicates improper certificate validation vulnerability
  • Details about affected platforms and versions
  • Information about lack of impact on VPN tunnel and mobile OS apps
  • Upgrade instructions specifying fixed versions
  • Statement of no known exploits currently
  • No workarounds available

Authoritative reference

Palo Alto Networks Security Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source