GlobalProtect App: Improper Certificate Validation Bypass Vulnerability

Plan PatchCVSS 7.4CVE-2026-0296Aug 12, 2026
Palo Alto NetworksTransportation
IT in OT - Palo Alto firewalls are commonly deployed at IT/OT network boundaries
Summary

Improper certificate validation in Palo Alto Networks GlobalProtect app on Windows, macOS, and Linux allows an unauthenticated attacker with man-in-the-middle access to intercept and modify application communications. An attacker positioned on the network path between a user's device and the Palo Alto gateway can present a fraudulent certificate and capture credentials or session tokens. VPN tunnel traffic is not impacted. iOS, Android, and Chrome OS versions are not affected. Multiple fixed versions are available depending on platform and current version: 6.3.3-h15 (Linux), 6.3.3-h14 / 6.3.3-1121 (macOS and Windows), 6.2.8-h13 / 6.2.8-1045 (macOS and Windows), and 6.0.15 (all platforms). Note that GlobalProtect App on Linux with version below 6.3.3-h15 is mentioned with a note that not all Linux versions have a fix available.

What this means
What could happen
An attacker positioned on the network between a user and the VPN gateway could intercept and modify GlobalProtect app communications, potentially stealing credentials or session tokens used for authentication. VPN tunnel traffic itself remains encrypted and is not affected.
Who's at risk
Organizations using Palo Alto Networks GlobalProtect app for remote VPN access on Windows, macOS, or Linux devices are affected. This includes employees working from home or untrusted networks, corporate contractors, and any user who authenticates to the Palo Alto gateway through the vulnerable app on these platforms. Mobile users on iOS, Android, or Chrome OS are not affected.
How it could be exploited
An attacker performs a man-in-the-middle (MitM) attack by positioning themselves on the network path between the user's device and the Palo Alto gateway—for example, on the same WiFi network or through compromised network infrastructure. The attacker presents a fraudulent SSL/TLS certificate to the GlobalProtect app, which fails to properly validate the certificate. The app accepts the fraudulent certificate and sends authentication traffic through the attacker's connection, allowing the attacker to capture credentials or session tokens.
Prerequisites
  • Attacker positioned on the network path between the user's device and the Palo Alto gateway (same WiFi, compromised router, etc.)
  • Vulnerable version of GlobalProtect app installed on Windows, macOS, or Linux (iOS, Android, Chrome OS not affected)
  • User initiates a connection to the VPN before connecting to the VPN tunnel
remotely exploitableno authentication required for MitM positioninglow complexity attackaffects authentication and credentialsolder Linux versions have no patch available
Exploitability
Unlikely to be exploited — EPSS score 0.1%
Affected products (9)
8 with fix1 pending
ProductAffected VersionsFix Status
GlobalProtect AppBelow 6.3.3-h15 on Linux6.3.3-h15 on Linux (ETA: 08/28)+
GlobalProtect AppBelow 6.3.3-h14 (6.3.3-1121) on macOS6.3.3-h14 (6.3.3-1121) on macOS+
GlobalProtect AppBelow 6.3.3-h14 (6.3.3-1121) on Windows6.3.3-h14 (6.3.3-1121) on Windows+
GlobalProtect AppAll on LinuxNo fix yet
GlobalProtect AppBelow 6.2.8-h13 (6.2.8-1045) on macOS6.2.8-h13 (6.2.8-1045) on macOS+
GlobalProtect AppBelow 6.2.8-h13 (6.2.8-1045) on Windows6.2.8-h13 (6.2.8-1045) on Windows+
GlobalProtect AppBelow 6.0.15 on Linux6.0.15 on Linux (ETA: 08/31)+
GlobalProtect AppBelow 6.0.15 on macOS6.0.15 on macOS (ETA: 08/31)+
Remediation & Mitigation
0/8
Schedule — requires maintenance window
0/6

Patching may require device reboot — plan for process interruption

GlobalProtect App
HOTFIXUpdate GlobalProtect app to version 6.3.3-h15 or later on Linux systems
HOTFIXUpdate GlobalProtect app to version 6.3.3-h14 (build 6.3.3-1121) or later on macOS systems
HOTFIXUpdate GlobalProtect app to version 6.3.3-h14 (build 6.3.3-1121) or later on Windows systems
HOTFIXUpdate GlobalProtect app to version 6.2.8-h13 (build 6.2.8-1045) or later on macOS systems if version 6.3.3 is not available
HOTFIXUpdate GlobalProtect app to version 6.2.8-h13 (build 6.2.8-1045) or later on Windows systems if version 6.3.3 is not available
HOTFIXUpdate GlobalProtect app to version 6.0.15 or later on all platforms (Windows, macOS, Linux) as an alternative if newer versions are not yet available
Long-term hardening
0/2
HARDENINGConfigure network segmentation to restrict direct access to untrusted WiFi networks and require VPN connection before accessing critical systems; encourage use of wired network connections for VPN gateway access when possible
HARDENINGDeploy certificate pinning or SSL inspection policies on your network to detect and block connections to unauthorized gateways attempting to intercept GlobalProtect traffic
API: /api/v1/advisories/aa4dc82f-3568-4d03-be23-3735272419c3

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.