← All Advisories

Palo Alto Networks GlobalProtect's Improper Certificate Validation Allows a Network Adversary to Present a Forged Certificate and Intercept the VPN Connection

Last refreshed2026-09-27

Status: EXPLOITED  |  Advisory ID: CVE-2026-0296

Key Details

CVECVE-2026-0296
CVSS Score / Version7.4 (High) / CVSS v3.1
Updated2026-09-20
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS Proseattack vector is network; attack complexity is high; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is none.
Affected productsPalo Alto Networks GlobalProtect
Exploitation statusPalo Alto Networks is not aware of any malicious exploitation of this issue.
Classified asCWE-295 (Improper Certificate Validation)
Exploitation prediction (EPSS)0.14% probability of exploitation in the next 30 days (3% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Palo Alto NetworksGlobalProtect
SubsystemsGeneral OT
SectorsMulti-sector

What to Know

Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted.

The GlobalProtect app on iOS, Android, and Chrome OS is not affected.

What to Do

GlobalProtect App: upgrade paths vary by platform/version (see the advisory's own version table); iOS, Android, and Chrome OS are not affected. No known workarounds beyond upgrading to a fixed release.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-0296
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-0296
Vendor advisoryhttps://security.paloaltonetworks.com/CVE-2026-0296