GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake

Plan PatchCVSS 7.7CVE-2026-0297Aug 12, 2026
Palo Alto Networks
IT in OT - Palo Alto firewalls are commonly deployed at IT/OT network boundaries
Summary

A buffer overflow vulnerability exists in Palo Alto Networks GlobalProtect app during UDP tunnel handshake processing. An attacker positioned between the client and gateway (man-in-the-middle) can send a malformed response that overflows a buffer in the app, causing a denial of service or potentially executing arbitrary code with elevated privileges (SYSTEM on Windows, root on macOS/Linux). The vulnerability affects GlobalProtect versions below 6.3.3-h15 on Linux, below 6.3.3-h14 on macOS/Windows, below 6.3.5 on iOS/Android/Chrome OS, and below 6.0.15 on multiple platforms. The Linux version has no patch available.

What this means
What could happen
An attacker positioned between a user and the VPN gateway during the UDP tunnel handshake could crash the GlobalProtect app or potentially execute code with system-level privileges, disrupting remote access and potentially compromising the endpoint.
Who's at risk
Organizations using Palo Alto Networks GlobalProtect app on Windows, macOS, Linux, iOS, Android, or Chrome OS endpoints. This primarily affects remote workers and users connecting through VPN, especially those using UDP tunnel mode for faster connections. Mobile and Linux users on certain versions have no available patch.
How it could be exploited
An attacker on the network path between a GlobalProtect client and gateway (man-in-the-middle) crafts a malicious response during the UDP tunnel handshake phase. The app fails to properly validate the response size, causing a buffer overflow that can crash the process or, with careful payload construction, execute arbitrary code with elevated privileges (SYSTEM/root).
Prerequisites
  • Network position to intercept UDP traffic between GlobalProtect client and gateway (man-in-the-middle capability)
  • Client must initiate UDP tunnel connection attempt
  • App must be below patched version for the target platform
remotely exploitableno authentication requiredaffects all endpoint platformsbuffer overflow with code execution potentialno patch available for GlobalProtect All on Linux
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (15)
14 with fix1 pending
ProductAffected VersionsFix Status
GlobalProtect AppBelow 6.3.3-h15 on Linux6.3.3-h15 on Linux (ETA: 08/28)+
GlobalProtect AppBelow 6.3.3-h14 (6.3.3-1121) on macOS6.3.3-h14 (6.3.3-1121) on macOS+
GlobalProtect AppBelow 6.3.3-h14 (6.3.3-1121) on Windows6.3.3-h14 (6.3.3-1121) on Windows+
GlobalProtect AppBelow 6.3.5 on iOS6.3.5 on iOS (ETA: 08/24)+
GlobalProtect AppBelow 6.3.5 on Android6.3.5 on Android (ETA: 08/18)+
GlobalProtect AppBelow 6.3.5 on Chrome OS6.3.5 on Chrome OS (ETA: 08/18)+
GlobalProtect AppAll on LinuxNo fix yet
GlobalProtect AppBelow 6.2.8-h13 (6.2.8-1045) on macOS6.2.8-h13 (6.2.8-1045) on macOS+
Remediation & Mitigation
0/4
Do now
0/3
WORKAROUNDDisable IPSec/UDP tunneling on GlobalProtect portal: Configure 'Connect with SSL Only' under Network > Portal > Agent Configuration > Advanced Control for Tunnel Mode Behavior to force SSL VPN connections only
WORKAROUNDDisable IPSec on GlobalProtect gateway: Uncheck 'Enable IPSec' under Network > Gateway > Agent > Tunnel Setting to prevent UDP tunnel negotiation
WORKAROUNDFor GlobalProtect 6.2.8 or 6.3.3 on Windows and macOS, enable strict certificate checking: Configure 'Enable Strict Certificate Check' under the GlobalProtect portal configuration (note: does not protect the first connection)
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

GlobalProtect App
HOTFIXUpdate GlobalProtect app to patched version: 6.3.3-h15 or later on Linux, 6.3.3-h14 (6.3.3-1121) or later on macOS/Windows, 6.3.5 or later on iOS/Android/Chrome OS, or 6.0.15 or later on all platforms
API: /api/v1/advisories/1ca02f36-cef9-492f-a5ea-342ccb71475e

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake | CVSS 7.7 - OTPulse