Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
SECURITY ADVISORYPALO ALTO NETWORKSVERIFIED

PUBLISHER UPDATE · CVE-2026-0296

CVE-2026-0296 release notes and known issues

GlobalProtect App: Improper Certificate Validation Bypass Vulnerability

Scope: GlobalProtect App. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted. The GlobalProtect app on iOS, Android, and Chrome OS is not affected.

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • GlobalProtect App

Affected versions

  • < 6.3.3-h15 on Linux, < 6.3.3-h14 (6.3.3-1121) on macOS, < 6.3.3-h14 (6.3.3-1121) on Windows
  • All on Linux, < 6.2.8-h13 (6.2.8-1045) on macOS, < 6.2.8-h13 (6.2.8-1045) on Windows
  • < 6.0.15 on Linux, < 6.0.15 on macOS, < 6.0.15 on Windows
  • None on iOS, None on Android, None on Chrome OS

Fixed versions or updates

  • >= 6.3.3-h15 on Linux (ETA: 09/17), >= 6.3.3-h14 (6.3.3-1121) on macOS, >= 6.3.3-h14 (6.3.3-1121) on Windows
  • None on Linux, >= 6.2.8-h13 (6.2.8-1045) on macOS, >= 6.2.8-h13 (6.2.8-1045) on Windows
  • >= 6.0.15 on Linux (ETA: 10/29), >= 6.0.15 on macOS (ETA: 10/29), >= 6.0.15 on Windows (ETA: 10/29)
  • All on iOS, All on Android, All on Chrome OS

Recommended action

VERSION MINOR VERSION SUGGESTED SOLUTION GlobalProtect App 6.3/6.2 on Linux 6.2.0 through 6.3.3-h14 Upgrade to 6.3.3-h15 or later. GlobalProtect App 6.0 on Linux 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later. GlobalProtect App 6.3 on macOS 6.3.0 through 6.3.3-h13 Upgrade to 6.3.3-h14 (6.3.3-1121) or later. GlobalProtect App 6.2 on macOS 6.2.0 through 6.2.8-h12 Upgrade to 6.2.8-h13 (6.2.8-1045) or later. GlobalProtect App 6.0 on macOS 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later. GlobalProtect App 6.3 on Windows 6.3.0 through 6.3.3-h13 Upgrade to 6.3.3-h14 (6.3.3-1121) or later. GlobalProtect App 6.2 on Windows 6.2.0 through 6.2.8-h12 Upgrade to 6.2.8-h13 (6.2.8-1045) or later. GlobalProtect App 6.0 on Windows 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later. GlobalProtect App on iOS No action needed. GlobalProtect App on Android No action needed. GlobalProtect App on Chrome OS No action needed.

Related vulnerabilities

BlackTree CVE Intelligence

Official publisher evidence

PALO ALTO NETWORKSVERIFIED

GlobalProtect App: Improper Certificate Validation Bypass Vulnerability

Checked 9 Oct 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.

Open the official publisher source