GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP)
Plan PatchCVSS 7.7CVE-2026-0298Aug 12, 2026
Palo Alto Networks
IT in OT - Palo Alto firewalls are commonly deployed at IT/OT network boundaries
Summary
An improper input validation vulnerability in the Windows Pre-Logon Access Provider (PLAP) component of Palo Alto Networks GlobalProtect app allows a man-in-the-middle attacker to execute arbitrary code with SYSTEM privileges on affected Windows clients during the pre-logon phase. The vulnerability affects GlobalProtect app versions below 6.3.3-h14 (6.3.3-1121) on Windows and below 6.2.8-h13 (6.2.8-1045) on the 6.2.x branch. GlobalProtect on Linux, macOS, iOS, Android, and Chrome OS is not affected.
What this means
What could happen
An attacker on the network path between a Windows computer and GlobalProtect gateway could run code with system privileges during user logon, potentially installing malware, stealing credentials, or disrupting VPN authentication before the user logs in.
Who's at risk
Windows-based employees and remote workers who use Palo Alto Networks GlobalProtect app for VPN access, particularly those connecting before logging into their workstations. Organizations with PLAP-based pre-logon access policies are at higher risk. This affects any industry relying on remote access for fieldwork, support, or distributed operations.
How it could be exploited
An attacker positioned between the Windows client and the GlobalProtect gateway (e.g., on the same network or via DNS hijacking) intercepts the pre-logon authentication traffic and sends a malicious response to the Windows PLAP component, which fails to validate the input properly and executes arbitrary code with SYSTEM privileges.
Prerequisites
- Network position on the path between Windows client and GlobalProtect gateway (man-in-the-middle capability)
- GlobalProtect app version below 6.3.3-h14 on Windows (or below 6.2.8-h13 for legacy versions)
- Pre-logon access provider (PLAP) feature enabled in GlobalProtect configuration
remotely exploitableno authentication requiredaffects critical logon phaseman-in-the-middle vectorCVSS 7.7 (high)
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (2)
2 with fix
ProductAffected VersionsFix Status
GlobalProtect AppBelow 6.3.3-h14 (6.3.3-1121) on Windows6.3.3-h14 (6.3.3-1121) on Windows+
GlobalProtect AppBelow 6.2.8-h13 (6.2.8-1045) on Windows6.2.8-h13 (6.2.8-1045) on Windows+
Remediation & Mitigation
0/5
Do now
0/2WORKAROUNDDisable Pre-Logon Access Provider (PLAP) and use Connect Before Logon (CBL) without SAML authentication instead
WORKAROUNDSwitch from Connect Before Logon (CBL) to Pre-logon with machine certificate authentication
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
GlobalProtect App
HOTFIXUpdate GlobalProtect app to version 6.3.3-h14 (6.3.3-1121) or later on all Windows clients
HOTFIXUpdate GlobalProtect app to version 6.2.8-h13 (6.2.8-1045) or later on Windows clients still on the 6.2.x branch
Long-term hardening
0/1HARDENINGImplement network segmentation to restrict pre-logon gateway traffic from untrusted network segments
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/17a9fa2d-e861-4c0f-a1a9-c37e55c5dc1eGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.