CVE-2026-0296 DetailsDescription Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted.
The GlobalProtect app on iOS, Android, and Chrome OS is not affected.
Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 SSVC
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 13, 2026 Exploitation: NoneAutomatable: NoTechnical Impact: Total
References to Advisories, Solutions, and Tools By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration Affected Products Product Versions paloaltonetworks globalprotect >= 6.0.0, < 6.0.15
>= 6.2.0, < 6.2.8
>= 6.2.0, <= 6.2.9
>= 6.3.0, < 6.3.3
6.2.8 -
6.2.8 h1
6.2.8 h10
6.2.8 h11
6.2.8 h12
6.2.8 h2
6.2.8 h3
6.2.8 h4
6.2.8 h5
6.2.8 h6
6.2.8 h7
6.2.8 h8
6.2.8 h9
6.3.3 -
6.3.3 h1
6.3.3 h11
6.3.3 h12
6.3.3 h2
6.3.3 h3
6.3.3 h4
6.3.3 h6
6.3.3 h7
6.3.3 h8
6.3.3 h9
Viewing 5 of 28 versions. View all CPE cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:linux:*:* cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:macos:*:* cpe:2.3:a:paloaltonetworks:globalprotect:*:*:*:*:*:windows:*:* cpe:2.3:a:paloaltonetworks:globalprotect:-:*:*:*:*:windows:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:-:*:*:*:macos:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h1:*:*:*:macos:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h10:*:*:*:macos:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h11:*:*:*:macos:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h12:*:*:*:macos:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h2:*:*:*:macos:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h3:*:*:*:macos:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h4:*:*:*:macos:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h5:*:*:*:macos:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h6:*:*:*:macos:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h7:*:*:*:macos:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h8:*:*:*:macos:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.2.8:h9:*:*:*:macos:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:-:*:*:*:linux:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:-:*:*:*:macos:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:-:*:*:*:windows:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h1:*:*:*:linux:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h1:*:*:*:macos:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h1:*:*:*:windows:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h11:*:*:*:macos:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h11:*:*:*:windows:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h12:*:*:*:macos:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h12:*:*:*:windows:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h2:*:*:*:linux:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h2:*:*:*:macos:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h2:*:*:*:windows:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h3:*:*:*:linux:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h3:*:*:*:macos:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h3:*:*:*:windows:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h4:*:*:*:macos:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h4:*:*:*:windows:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h6:*:*:*:macos:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h6:*:*:*:windows:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h7:*:*:*:macos:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h7:*:*:*:windows:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h8:*:*:*:macos:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h8:*:*:*:windows:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h9:*:*:*:macos:*:* cpe:2.3:a:paloaltonetworks:globalprotect:6.3.3:h9:*:*:*:windows:*:* Remediation No remediation found in references.
Change History 3 change records found show changes