CVE-2026-0296
published 2026-08-13CVE-2026-0296: Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM)…
PriorityP419medium4.5CVSS 4.0
AVAACLATPPRNUIPVCHVIHVANSCNSINSANEUCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUNRUVDREMUAmber
EPSS
0.09%
0.6th percentile
Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted.
The GlobalProtect app on iOS, Android, and Chrome OS is not affected.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| palo_alto_networks | globalprotect_app | — | — |
| palo_alto_networks | globalprotect_app | >= 6.0.0 < 6.0.15 | 6.0.15 |
| palo_alto_networks | globalprotect_app | >= 6.2.0 < 6.2.8-h13 | 6.2.8-h13 |
| palo_alto_networks | globalprotect_app | >= 6.3.0 < 6.3.3-h15 | 6.3.3-h15 |
| palo_alto_networks | globalprotect_app | >= 6.3.0 < 6.3.3-h14 | 6.3.3-h14 |
| paloalto | globalprotect_app | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application com
ghsa_unreviewed·2026-08-13
CVE-2026-0296 [MEDIUM] CWE-295 Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application com
Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted.
The GlobalProtect app on iOS, Android, and Chrome OS is not affected.
Palo Alto
GlobalProtect App: Improper Certificate Validation Bypass Vulnerability
vendor_paloalto·CVSS 7.4
CVE-2026-0296 CWE-295 GlobalProtect App: Improper Certificate Validation Bypass Vulnerability
GlobalProtect App: Improper Certificate Validation Bypass Vulnerability
Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted.
The GlobalProtect app on iOS, Android, and Chrome OS is not affected.
Affected products: GlobalProtect App
Solution: VERSION MINOR VERSION SUGGESTED SOLUTION
GlobalProtect App 6.3/6.2 on Linux 6.2.0 through 6.3.3-h14 Upgrade to 6.3.3-h15 or later.
GlobalProtect App 6.0 on Linux 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later.
GlobalProtect App 6.3 on macOS 6.3.0 through 6.3.3-h13 Upgrade to 6.3.3-h14 (6.3.3-1121) or later.
GlobalProtect App 6.2 on macOS 6.2.0 through 6
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-13
Published