{"id":"CVE-2026-0296","title":"Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications","summary":"Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is no…","severity":"high","cvss":7.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-295"],"vendor":"paloaltonetworks","product":"globalprotect","affected":["globalprotect >= 6.0.0, < 6.0.15","globalprotect >= 6.2.0, < 6.2.8","globalprotect >= 6.2.0, <= 6.2.9","globalprotect >= 6.3.0, < 6.3.3","globalprotect","globalprotect = 6.2.8","globalprotect = 6.3.3"],"patched":["globalprotect 6.3.3"],"published":"2026-08-13","updated":"2026-09-10","sourceUpdated":"2026-09-10T17:09:30.590","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-0296","references":[{"url":"https://security.paloaltonetworks.com/CVE-2026-0296","label":"psirt@paloaltonetworks.com"}],"tags":["nvd"],"epss":0.00138,"epssPercentile":0.03578,"ingestedAt":"2026-09-10T18:02:18.300Z","slug":"CVE-2026-0296","body":"## Overview\n\nImproper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted.\n\nThe GlobalProtect app on iOS, Android, and Chrome OS is not affected.\n\n## Affected\n\n- `globalprotect >= 6.0.0, < 6.0.15`\n- `globalprotect >= 6.2.0, < 6.2.8`\n- `globalprotect >= 6.2.0, <= 6.2.9`\n- `globalprotect >= 6.3.0, < 6.3.3`\n- `globalprotect`\n- `globalprotect = 6.2.8`\n- `globalprotect = 6.3.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `globalprotect 6.3.3`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":40.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}