Junglewise Threat Intelligence

CVE-2026-0249: Palo Alto Networks GlobalProtect improper certificate validation

CVE-2026-0249 · Severity: medium · CVSS 6.5 · Published 2026-05-13

Technologies: Palo Alto Networks GlobalProtect App. Vendors: Palo Alto Networks.

Executive brief

Palo Alto Networks GlobalProtect is a security application used to provide secure VPN access for remote employees. A vulnerability in certain versions for macOS, Android, and ChromeOS allows attackers on the same network to intercept and redirect encrypted traffic to malicious servers. This could lead to the installation of unauthorized software or the compromise of the user's device.

Technical details

The vulnerability is classified as CWE-295 (Improper Certificate Validation), which allows for Adversary-in-the-Middle (AiTM) attacks. On macOS, the issue is specifically triggered when SAML authentication with an embedded browser is enabled; on Android and ChromeOS, no special configuration is required. An attacker positioned on the same subnet or a local non-administrative user can redirect traffic to an unauthorized server, facilitating traffic interception or malicious software installation. The GlobalProtect app for Windows, Linux, and iOS is not affected. Patches are available in versions 6.0.13/6.0.14, 6.1.14, 6.2.8-h10, and 6.3.3-h9 depending on the platform.

Affected products

  • Palo Alto Networks GlobalProtect App macOS: 6.0.0 to 6.0.12, 6.2.0 to 6.2.8-h9, 6.3.0 to 6.3.3-h8; Android/ChromeOS: 6.0.0 to 6.0.13, 6.1.0 to 6.1.13

Timeline

  • 2026-05-13: advisory: Initial publication by Palo Alto Networks
  • 2026-06-13: patched: Updated patch availability for Android and ChromeOS versions

References

Related threats