Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
SECURITY ADVISORYPALO ALTO NETWORKSVERIFIED

PUBLISHER UPDATE · CVE-2026-0297

CVE-2026-0297 release notes and known issues

GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake

Scope: GlobalProtect App. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated privileges (SYSTEM privileges on Windows, and root privileges on macOS and Linux).

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • GlobalProtect App

Affected versions

  • < 6.3.3-h15 on Linux, < 6.3.3-h14 on macOS, < 6.3.3-h14 on Windows, < 6.3.5 on iOS, < 6.3.5 on Android, < 6.3.5 on Chrome OS
  • All on Linux, < 6.2.8-h13 on macOS, < 6.2.8-h13 on Windows
  • < 6.0.15 on Linux, < 6.0.15 on macOS, < 6.0.15 on Windows, < 6.0.15 on iOS, < 6.0.15 on Android, < 6.0.15 on Chrome OS

Fixed versions or updates

  • >= 6.3.3-h15 on Linux (ETA: 09/17), >= 6.3.3-h14 on macOS, >= 6.3.3-h14 on Windows, >= 6.3.5 on iOS, >= 6.3.5 on Android, >= 6.3.5 on Chrome OS
  • None on Linux, >= 6.2.8-h13 on macOS, >= 6.2.8-h13 on Windows
  • >= 6.0.15 on Linux (ETA: 10/29), >= 6.0.15 on macOS (ETA: 10/29), >= 6.0.15 on Windows (ETA: 10/29), >= 6.0.15 on iOS (ETA: 10/29), >= 6.0.15 on Android (ETA: 10/29), >= 6.0.15 on Chrome OS (ETA: 10/29)

Recommended action

VERSION MINOR VERSION SUGGESTED SOLUTION GlobalProtect App 6.3/6.2 on Linux 6.2.0 through 6.3.3-h14 Upgrade to 6.3.3-h15 or later. GlobalProtect App 6.0 on Linux 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later. GlobalProtect App 6.3 on macOS 6.3.0 through 6.3.3-h13 Upgrade to 6.3.3-h14 (6.3.3-1121) or later. GlobalProtect App 6.2 on macOS 6.2.0 through 6.2.8-h12 Upgrade to 6.2.8-h13 (6.2.8-1045) or later. GlobalProtect App 6.0 on macOS 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later. GlobalProtect App 6.3 on Windows 6.3.0 through 6.3.3-h13 Upgrade to 6.3.3-h14 (6.3.3-1121) or later. GlobalProtect App 6.2 on Windows 6.2.0 through 6.2.8-h12 Upgrade to 6.2.8-h13 (6.2.8-1045) or later. GlobalProtect App 6.0 on Windows 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later. GlobalProtect App 6.3/6.1 on iOS 6.1.0 through 6.3.4 Upgrade to 6.3.5 or later. GlobalProtect App 6.0 on iOS 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later. GlobalProtect App 6.3/6.1 on Android 6.1.0 through 6.3.4 Upgrade to 6.3.5 or later. GlobalProtect App 6.0 on Android 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later. GlobalProtect App 6.3/6.1 on ChromeOS 6.1.0 through 6.3.4 Upgrade to 6.3.5 or later. GlobalProtect App 6.0 on ChromeOS 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later.

Related vulnerabilities

BlackTree CVE Intelligence

Official publisher evidence

PALO ALTO NETWORKSVERIFIED

GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake

Checked 9 Oct 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.

Open the official publisher source