Security Advisory Desk
mediumQCS priority 76/100Palo Alto Networks

CVE-2026-0297 GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake (Severity: MEDIUM)

A security flaw was found in the Palo Alto Networks GlobalProtect app. This flaw is a buffer overflow that happens during a UDP tunnel handshake, which could let attackers disrupt the app or run harmful code with high-level system access on Windows, macOS, or Linux. No special settings are needed for the flaw to be present. Palo Alto Networks has released updated app versions to address this issue and provides mitigation steps if immediate updates are not possible.

Published 12/9/2026, 12:30:00 amVerified 16/9/2026, 6:45:41 amRevision 2
Palo Alto Networks medium network security advisory visual

In plain language

What this advisory means

A security flaw was found in the Palo Alto Networks GlobalProtect app. This flaw is a buffer overflow that happens during a UDP tunnel handshake, which could let attackers disrupt the app or run harmful code with high-level system access on Windows, macOS, or Linux. No special settings are needed for the flaw to be present. Palo Alto Networks has released updated app versions to address this issue and provides mitigation steps if immediate updates are not possible.

Technical explanation

How the issue affects the environment

The vulnerability CVE-2026-0297 in the GlobalProtect app is a buffer overflow occurring during the UDP tunnel handshake. This memory corruption flaw allows a man-in-the-middle attacker or malicious gateway to overwrite memory outside the intended buffer (CWE-787). Exploiting this enables them to disrupt system processes or execute arbitrary code with SYSTEM privileges on Windows or root privileges on macOS and Linux. Attack complexity is low, with no user interaction required, and the exploit vector is adjacent network access. Updated patched versions are available across supported platforms. Configuration changes like enforcing SSL-only VPN connections or enabling strict certificate checks serve as mitigations.

Operational impact

Why teams should care

Successful exploitation could lead to severe disruption of GlobalProtect VPN clients and compromise of endpoint security, with attackers gaining elevated system privileges. This puts organizational confidentiality, integrity, and availability of devices using GlobalProtect at high risk. Timely upgrade or workaround implementations are critical to maintain secure remote access operations and protect sensitive corporate resources.

Immediate action

Upgrade GlobalProtect app to the fixed versions listed per platform. If immediate upgrade is not feasible, configure GlobalProtect Portal to enforce SSL-only VPN connections by disabling IPSec/UDP tunneling. Enable strict certificate validation settings on supported platforms (Windows and macOS). Mobile device management (MDM) can enforce full-chain certificate verification for mobile platforms.

Affected and fixed releases

Affected versionsGlobalProtect app 6.3.0 up to but excluding 6.3.3-h15 on Linux, 6.3.0 up to 6.3.3-h14 on macOS and Windows, 6.2.0 up to 6.2.8-h13 on macOS and Windows, 6.0.0 up to 6.0.15 on all platforms, 6.3.0 up to 6.3.5 on iOS, Android, Chrome OS
Fixed versions6.3.3-h15 or later on Linux, 6.3.3-h14 or later on macOS and Windows, 6.2.8-h13 or later on macOS and Windows, 6.0.15 or later on all platforms, 6.3.5 or later on iOS, Android, Chrome OS

Temporary risk reduction

As a mitigation, disable IPSec/UDP tunnels to force SSL-only VPN use. On Windows and macOS, enable 'Strict Certificate Check' to require certificate validation after first connection. For macOS, edit the settings plist to enable full-chain certificate verification. On Linux, deploy a pre-configuration XML file for certificate verification. Mobile platforms can apply MDM policies to enable certificate verification settings.

Evidence and validation checklist

  • Palo Alto Networks Security Advisory for CVE-2026-0297
  • Official fixed version release notes and upgrade instructions
  • Mitigation configuration guidelines from Palo Alto Networks
  • Platform and version impact details as published by vendor

Authoritative reference

Palo Alto Networks Security Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source
CVE-2026-0297 GlobalProtect App: Buffer Overflow | Advisory | QCS