{"id":"CVE-2026-0297","title":"A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated priv…","summary":"A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated priv…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-787"],"vendor":"paloaltonetworks","product":"globalprotect","affected":["globalprotect >= 6.0.0, < 6.0.15","globalprotect >= 6.2.0, < 6.2.8","globalprotect >= 6.2.0, <= 6.2.9","globalprotect >= 6.3.0, < 6.3.3","globalprotect >= 6.3.0, < 6.3.5","globalprotect = 6.2.8","globalprotect = 6.3.3"],"patched":["globalprotect 6.3.5"],"published":"2026-08-13","updated":"2026-09-10","sourceUpdated":"2026-09-10T17:07:52.880","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-0297","references":[{"url":"https://security.paloaltonetworks.com/CVE-2026-0297","label":"psirt@paloaltonetworks.com"}],"tags":["nvd","cve.org","score-dispute"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-08-13T03:55:54.896353Z"},"scores":{"nvd":8.1,"cna":5.2},"ingestedAt":"2026-09-11T12:26:22.700Z","epss":0.0031,"epssPercentile":0.2395,"slug":"CVE-2026-0297","body":"## Overview\n\nA buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated privileges (SYSTEM privileges on Windows, and root privileges on macOS and Linux).\n\n## Affected\n\n- `globalprotect >= 6.0.0, < 6.0.15`\n- `globalprotect >= 6.2.0, < 6.2.8`\n- `globalprotect >= 6.2.0, <= 6.2.9`\n- `globalprotect >= 6.3.0, < 6.3.3`\n- `globalprotect >= 6.3.0, < 6.3.5`\n- `globalprotect = 6.2.8`\n- `globalprotect = 6.3.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `globalprotect 6.3.5`","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}