Status: EXPLOITED | Advisory ID: CVE-2026-0298
| CVE | CVE-2026-0298 |
| CVSS Score / Version | 8.1 (High) / CVSS v3.1 |
| Updated | 2026-09-20 |
| CVSS Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is high; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Palo Alto Networks GlobalProtect |
| Exploitation status | Palo Alto Networks is not aware of any malicious exploitation of this issue. |
| Classified as | CWE-94 (Improper Control of Generation of Code ('Code Injection')) |
| Exploitation prediction (EPSS) | 0.33% probability of exploitation in the next 30 days (24% percentile) -- FIRST.org's EPSS model. |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Palo Alto Networks | GlobalProtect |
| Subsystems | General OT |
| Sectors | Multi-sector |
An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client.
The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.
GlobalProtect App 6.3 on Windows (6.3.0 through 6.3.3-h13): upgrade to 6.3.3-h14 (6.3.3-1121) or later. 6.2 on Windows (6.2.0 through 6.2.8-h12): upgrade to 6.2.8-h13 (6.2.8-1045) or later. 6.0 on Windows (6.0.0 through 6.0.14): upgrade to 6.0.15 or later. macOS/Linux/iOS/Android/Chrome OS: no action needed.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-0298 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2026-0298 |
| Vendor advisory | https://security.paloaltonetworks.com/CVE-2026-0298 |