Junglewise Threat Intelligence

CVE-2026-0250: Palo Alto Networks GlobalProtect buffer overflow in Portal/Gateway communication

CVE-2026-0250 · Severity: high · CVSS 8.1 · Published 2026-05-13

Technologies: Palo Alto Networks GlobalProtect App. Vendors: Palo Alto Networks.

Executive brief

A security vulnerability has been identified in the Palo Alto Networks GlobalProtect app, which is used to provide secure remote access to corporate networks. An attacker positioned between a user's device and the corporate gateway could exploit this flaw to disrupt the connection or potentially take full control of the user's computer with administrative privileges. This issue affects versions on Windows, macOS, Linux, Android, and ChromeOS, but does not impact iOS devices.

Technical details

A stack-based buffer overflow (CWE-787) exists in the Palo Alto Networks GlobalProtect app during the processing of requests and responses exchanged between the Portal and Gateway. The vulnerability can be triggered by a man-in-the-middle (MitM) attacker with an adjacent network position. Successful exploitation allows the attacker to disrupt system processes or achieve arbitrary code execution with SYSTEM privileges on the host operating system. The vulnerability affects multiple platforms including Windows, macOS, Linux, Android, and ChromeOS, while the iOS version is explicitly noted as unaffected. Security updates have been released for all affected branches.

Affected products

  • Palo Alto Networks GlobalProtect App 6.0.x, 6.1.x, 6.2.x, 6.3.x (Windows, macOS, Linux, Android, ChromeOS)
  • Palo Alto Networks GlobalProtect UWP App 6.1.0 through 6.3.3-h9

Timeline

  • 2026-05-13: advisory: Initial advisory publication
  • 2026-06-13: other: Advisory updated

References

Related threats