GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP)
Checked 9 Oct 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.
Open the official publisher sourcePUBLISHER UPDATE · CVE-2026-0298
GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP)
Scope: GlobalProtect App. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.
An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client. The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.
Not stated. The verified publisher record does not contain a known-issues statement.
VERSION MINOR VERSION SUGGESTED SOLUTION GlobalProtect App 6.3 on Windows 6.3.0 through 6.3.3-h13 Upgrade to 6.3.3-h14 (6.3.3-1121) or later. GlobalProtect App 6.2 on Windows 6.2.0 through 6.2.8-h12 Upgrade to 6.2.8-h13 (6.2.8-1045) or later. GlobalProtect App 6.0 on Windows 6.0.0 through 6.0.14 Upgrade to 6.0.15 or later. GlobalProtect App All on macOS No action needed. GlobalProtect App All on Linux No action needed. GlobalProtect App All on iOS No action needed. GlobalProtect App All on Android No action needed. GlobalProtect App All on Chrome OS No action needed.
Checked 9 Oct 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.
Open the official publisher source