Security Advisory Desk
mediumQCS priority 76/100Palo Alto Networks

CVE-2026-0297 GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake (Severity: MEDIUM)

A security flaw in the Palo Alto Networks GlobalProtect app’s handshake process for UDP tunnels can cause the app to crash or allow attackers to run harmful code on your computer with administrative rights. This could let bad actors interrupt your system or take full control of it. Updating the app to the latest versions fixes the vulnerability. If you cannot update immediately, you can change settings to use safer connection methods or configurations to reduce the risk.

Published 12/8/2026, 4:00:00 pmVerified 12/8/2026, 9:59:02 pmRevision 1
Palo Alto Networks medium network security advisory visual

In plain language

What this advisory means

A security flaw in the Palo Alto Networks GlobalProtect app’s handshake process for UDP tunnels can cause the app to crash or allow attackers to run harmful code on your computer with administrative rights. This could let bad actors interrupt your system or take full control of it. Updating the app to the latest versions fixes the vulnerability. If you cannot update immediately, you can change settings to use safer connection methods or configurations to reduce the risk.

Technical explanation

How the issue affects the environment

CVE-2026-0297 is a buffer overflow vulnerability in the Palo Alto Networks GlobalProtect app that occurs during the UDP tunnel handshake process. This flaw allows a man-in-the-middle attacker or a malicious gateway to write data beyond buffer boundaries, leading to disruption of system processes and potential execution of arbitrary code with SYSTEM privileges on Windows, and root privileges on macOS and Linux. The vulnerability does not require user interaction or privileges, and can be triggered through adjacent network access vectors via the UDP tunnel handshake. Mitigations include disabling IPSec/UDP tunneling to enforce SSL-only VPN connections, enabling strict certificate checks on Windows and macOS, and applying device management settings on mobile platforms. Vendor released fixed versions addressing this vulnerability across Linux, macOS, Windows, iOS, Android, and Chrome OS platforms.

Operational impact

Why teams should care

This vulnerability can allow attackers to disrupt critical VPN client processes and potentially take full control over affected endpoints. This compromises the confidentiality, integrity, and availability of devices using the GlobalProtect app. Successful exploitation could lead to system downtime, unauthorized access, data breach, and erosion of trust in company IT security. Organizations should prioritize updating the GlobalProtect app or applying recommended mitigations to protect their remote workforce and secure network access.

Immediate action

Upgrade the GlobalProtect app to the versions listed as fixed: 6.3.3-h15 or later for Linux, 6.2.8-h13 or later for macOS and Windows, 6.0.15 or later for all platforms including mobile, and 6.3.5 or later for iOS, Android, and Chrome OS. These versions address the buffer overflow vulnerability during UDP tunnel handshake by correcting input validation and memory handling.

Affected and fixed releases

Affected versionsGlobalProtect App 6.3 from 6.3.0 up to but excluding 6.3.3-h15 on Linux, GlobalProtect App 6.2.0 through 6.3.3-h14 on Linux, GlobalProtect App 6.0.0 through 6.0.14 on Linux, GlobalProtect App 6.3.0 through 6.3.3-h13 on macOS, GlobalProtect App 6.2.0 through 6.2.8-h12 on macOS, GlobalProtect App 6.0.0 through 6.0.14 on macOS, GlobalProtect App 6.3.0 through 6.3.3-h13 on Windows, GlobalProtect App 6.2.0 through 6.2.8-h12 on Windows, GlobalProtect App 6.0.0 through 6.0.14 on Windows, GlobalProtect App 6.3.0 through 6.3.4 on iOS, GlobalProtect App 6.0.0 through 6.0.14 on iOS, GlobalProtect App 6.3.0 through 6.3.4 on Android, GlobalProtect App 6.0.0 through 6.0.14 on Android, GlobalProtect App 6.3.0 through 6.3.4 on Chrome OS, GlobalProtect App 6.0.0 through 6.0.14 on Chrome OS
Fixed versionsGlobalProtect App 6.3.3-h15 or later on Linux, GlobalProtect App 6.2.8-h13 or later on macOS and Windows, GlobalProtect App 6.0.15 or later on Linux, macOS, Windows, iOS, Android, Chrome OS, GlobalProtect App 6.3.3-h14 or later on macOS and Windows, GlobalProtect App 6.3.5 or later on iOS, Android, Chrome OS

Temporary risk reduction

To reduce risk before upgrading, enforce SSL-only VPN connections by disabling IPSec/UDP tunneling in GlobalProtect Portal and Gateway configurations. On Windows and macOS, enable the 'Enable Strict Certificate Check' setting to require certificate validation against rogue gateways after the initial connection. For macOS, edit the preference plist to set 'full-chain-cert-verify' to 'yes'. On Linux, pre-deployment configuration with pangps.xml containing this setting can help. For mobile platforms, apply MDM policies to enforce full-chain certificate verification. These mitigations prevent exploitation by avoiding vulnerable UDP handshake methods or ensuring strict certificate checks.

Evidence and validation checklist

  • Palo Alto Networks original security advisory at https://security.paloaltonetworks.com/CVE-2026-0297
  • Details of vulnerability CVE-2026-0297 including affected versions and fixed releases
  • Description of buffer overflow during UDP tunnel handshake
  • Mitigation steps including enforcing SSL-only connections and certificate verification
  • No reports of exploitation as stated by vendor

Authoritative reference

Palo Alto Networks Security Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source