Security Advisory Desk
mediumQCS priority 76/100Palo Alto Networks

CVE-2026-0296 GlobalProtect App: Improper Certificate Validation Bypass Vulnerability (Severity: MEDIUM)

A security weakness in the GlobalProtect app from Palo Alto Networks allows attackers who can intercept your internet connection to bypass certificate checks. This means attackers could intercept and tamper with some app communications. However, your main VPN traffic remains secure. The issue does not affect GlobalProtect on iOS, Android, or Chrome OS.

Published 12/8/2026, 4:00:00 pmVerified 12/8/2026, 6:30:55 pmRevision 1
Palo Alto Networks medium network security advisory visual

In plain language

What this advisory means

A security weakness in the GlobalProtect app from Palo Alto Networks allows attackers who can intercept your internet connection to bypass certificate checks. This means attackers could intercept and tamper with some app communications. However, your main VPN traffic remains secure. The issue does not affect GlobalProtect on iOS, Android, or Chrome OS.

Technical explanation

How the issue affects the environment

The vulnerability (CVE-2026-0296) in Palo Alto Networks' GlobalProtect app involves improper validation of certificates used in the app's communication. This flaw permits an unauthenticated attacker with man-in-the-middle (MitM) capabilities on an adjacent network to intercept and modify the GlobalProtect app's communications by bypassing certificate validation. Importantly, this vulnerability does not impact the VPN tunnel traffic itself. The issue affects versions on Linux, macOS, and Windows platforms, but not on iOS, Android, or Chrome OS. No special configuration is necessary to be vulnerable, indicating that all affected versions are exposed by default.

Operational impact

Why teams should care

This vulnerability could allow attackers positioned on the same or nearby network to intercept and alter communications of the GlobalProtect app, potentially exposing sensitive data or enabling spoofing attacks. While the VPN tunnel traffic remains protected, compromised app communications may impact confidentiality and data integrity. This could affect organizational security posture and compliance requirements. No evidence currently indicates active exploitation, but timely updates are advised to mitigate potential risks.

Immediate action

To address this vulnerability, update your GlobalProtect app to the specified fixed versions or later for your platform. These updates correct the certificate validation process, preventing attackers from bypassing it. Users on iOS, Android, and Chrome OS are not affected and require no action.

Affected and fixed releases

Affected versionsGlobalProtect App 6.3.x on Linux before 6.3.3-h15, GlobalProtect App 6.2.x on Linux before 6.2.8-h13, GlobalProtect App 6.0.x on Linux before 6.0.15, GlobalProtect App 6.3.x on macOS before 6.3.3-h14, GlobalProtect App 6.2.x on macOS before 6.2.8-h13, GlobalProtect App 6.0.x on macOS before 6.0.15, GlobalProtect App 6.3.x on Windows before 6.3.3-h14, GlobalProtect App 6.2.x on Windows before 6.2.8-h13, GlobalProtect App 6.0.x on Windows before 6.0.15
Fixed versionsGlobalProtect App 6.3.3-h15 on Linux and later, GlobalProtect App 6.2.8-h13 on Linux and later, GlobalProtect App 6.0.15 on Linux and later, GlobalProtect App 6.3.3-h14 on macOS and later, GlobalProtect App 6.2.8-h13 on macOS and later, GlobalProtect App 6.0.15 on macOS and later, GlobalProtect App 6.3.3-h14 on Windows and later, GlobalProtect App 6.2.8-h13 on Windows and later, GlobalProtect App 6.0.15 on Windows and later

Temporary risk reduction

There are no known workarounds or mitigations for this issue. Applying the vendor's updates is the recommended approach to resolve the vulnerability.

Evidence and validation checklist

  • Vulnerability enables certificate validation bypass in GlobalProtect app communications.
  • Unauthenticated attacker with man-in-the-middle access can intercept and modify app communications.
  • VPN tunnel traffic remains unaffected.
  • Issue affects Linux, macOS, and Windows versions, not iOS, Android, or Chrome OS.
  • No special configuration is needed to be vulnerable.
  • Vendor provides specific fixed versions to upgrade to.
  • No known workarounds or mitigations exist.
  • No reported exploitation in the wild at the time of advisory publication.

Authoritative reference

Palo Alto Networks Security Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source
CVE-2026-0296 GlobalProtect App: Improper | Advisory | QCS