Palo Alto updates GlobalProtect fixes after multiple privilege escalation and code-execution vulnerabilities

Palo Alto Networks has released security advisories for critical flaws in its GlobalProtect app, exposing users to privilege escalation and remote code execution risks across Windows, Linux, and macOS platforms, prompting urgent patching efforts.

Palo Alto Networks has issued security advisories for a set of flaws in its GlobalProtect app that could let a local attacker on a Windows device gain SYSTEM-level privileges or escalate to root on Linux and macOS. The company published the advisories on August 12 and said the issues affect GlobalProtect app versions 6.0, 6.2 and 6.3 across desktop operating systems.

The most important issue is CVE-2026-0299, a local privilege-escalation bug with a CVSS score of 5.9. Palo Alto said an authenticated local user could use it to raise their permissions, turning limited access into control over security-sensitive processes and files. The flaw affects Linux builds before 6.3.3-h15 and Windows and macOS builds before 6.3.3-h14, with older 6.2 and 6.0 branches also exposed.

Patches are already available for some 6.3 releases on Windows and macOS, while fixes for Linux are due by August 28 and updates for the 6.0 branch are scheduled for August 31. Palo Alto said iOS, Android and ChromeOS are not affected by CVE-2026-0299.

The advisory also covers CVE-2026-0298, a Windows-only code-execution flaw in the GlobalProtect Windows Pre-Logon Access Provider, or PLAP, rated 5.2. Because PLAP runs before a normal user session begins, this part of the client is especially important for organisations that use pre-logon VPN connections for managed endpoints. Palo Alto said the issue affects versions before 6.3.3-h14 and 6.2.8-h13, with 6.0.15 expected to close the gap in the legacy branch.

Two other vulnerabilities are also under advisement. CVE-2026-0297, another 5.2-rated issue, is a buffer overflow in the UDP tunnel handshake that affects Linux, Windows, macOS, iOS, Android and ChromeOS clients. CVE-2026-0296, rated 4.5, involves improper certificate validation on Linux, Windows and macOS and could weaken trust checks in some network conditions. Security teams should inventory GlobalProtect deployments, apply available hotfixes, restrict local administrative access where possible and watch for unusual changes to client binaries, services, certificates or configuration files.

The new disclosures add to a string of security problems affecting Palo Alto’s VPN software this year. CISA warned in June about CVE-2026-0257, a critical authentication-bypass flaw in PAN-OS GlobalProtect portal and gateway components that it added to its Known Exploited Vulnerabilities catalogue. Earlier this year, Palo Alto also fixed a high-severity denial-of-service bug, CVE-2026-0227, in GlobalProtect Gateway and Portal software. Together, the advisories underline continued pressure on organisations that rely on the product for remote access.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.