In plain language
What this advisory means
A security flaw in the Palo Alto Networks GlobalProtect app’s handshake process for UDP tunnels can cause the app to crash or allow attackers to run harmful code on your computer with administrative rights. This could let bad actors interrupt your system or take full control of it. Updating the app to the latest versions fixes the vulnerability. If you cannot update immediately, you can change settings to use safer connection methods or configurations to reduce the risk.
Technical explanation
How the issue affects the environment
CVE-2026-0297 is a buffer overflow vulnerability in the Palo Alto Networks GlobalProtect app that occurs during the UDP tunnel handshake process. This flaw allows a man-in-the-middle attacker or a malicious gateway to write data beyond buffer boundaries, leading to disruption of system processes and potential execution of arbitrary code with SYSTEM privileges on Windows, and root privileges on macOS and Linux. The vulnerability does not require user interaction or privileges, and can be triggered through adjacent network access vectors via the UDP tunnel handshake. Mitigations include disabling IPSec/UDP tunneling to enforce SSL-only VPN connections, enabling strict certificate checks on Windows and macOS, and applying device management settings on mobile platforms. Vendor released fixed versions addressing this vulnerability across Linux, macOS, Windows, iOS, Android, and Chrome OS platforms.
Operational impact
Why teams should care
This vulnerability can allow attackers to disrupt critical VPN client processes and potentially take full control over affected endpoints. This compromises the confidentiality, integrity, and availability of devices using the GlobalProtect app. Successful exploitation could lead to system downtime, unauthorized access, data breach, and erosion of trust in company IT security. Organizations should prioritize updating the GlobalProtect app or applying recommended mitigations to protect their remote workforce and secure network access.
Immediate action
Upgrade the GlobalProtect app to the versions listed as fixed: 6.3.3-h15 or later for Linux, 6.2.8-h13 or later for macOS and Windows, 6.0.15 or later for all platforms including mobile, and 6.3.5 or later for iOS, Android, and Chrome OS. These versions address the buffer overflow vulnerability during UDP tunnel handshake by correcting input validation and memory handling.
Affected and fixed releases
Temporary risk reduction
To reduce risk before upgrading, enforce SSL-only VPN connections by disabling IPSec/UDP tunneling in GlobalProtect Portal and Gateway configurations. On Windows and macOS, enable the 'Enable Strict Certificate Check' setting to require certificate validation against rogue gateways after the initial connection. For macOS, edit the preference plist to set 'full-chain-cert-verify' to 'yes'. On Linux, pre-deployment configuration with pangps.xml containing this setting can help. For mobile platforms, apply MDM policies to enforce full-chain certificate verification. These mitigations prevent exploitation by avoiding vulnerable UDP handshake methods or ensuring strict certificate checks.
Evidence and validation checklist
- Palo Alto Networks original security advisory at https://security.paloaltonetworks.com/CVE-2026-0297
- Details of vulnerability CVE-2026-0297 including affected versions and fixed releases
- Description of buffer overflow during UDP tunnel handshake
- Mitigation steps including enforcing SSL-only connections and certificate verification
- No reports of exploitation as stated by vendor
Authoritative reference
Palo Alto Networks Security Advisories
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
