8.1

CVE-2026-0250

GlobalProtect App: Buffer Overflow Vulnerability during connection to Portal or Gateway

A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man in the middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges. This vulnerability is triggered during the processing of requests and responses exchanged between Portal and Gateway.



The GlobalProtect app on iOS is not affected.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PaloaltonetworksGlobalprotect SwPlatformlinux Version >= 6.0.0 < 6.0.12
PaloaltonetworksGlobalprotect SwPlatformmacos Version >= 6.0.0 < 6.0.13
PaloaltonetworksGlobalprotect SwPlatformwindows Version >= 6.0.0 < 6.0.13
PaloaltonetworksGlobalprotect SwPlatformandroid Version >= 6.0.0 < 6.0.15
PaloaltonetworksGlobalprotect SwPlatformchrome Version >= 6.0.0 < 6.0.15
PaloaltonetworksGlobalprotect SwPlatformandroid Version >= 6.1.0 < 6.1.14
PaloaltonetworksGlobalprotect SwPlatformchrome Version >= 6.1.0 < 6.1.14
PaloaltonetworksGlobalprotect SwPlatformmacos Version >= 6.2.0 < 6.2.8
PaloaltonetworksGlobalprotect SwPlatformwindows Version >= 6.2.0 < 6.2.8
PaloaltonetworksGlobalprotect SwPlatformuniversal_windows_platform Version >= 6.3.0 < 6.3.3
PaloaltonetworksGlobalprotect SwPlatformwindows Version >= 6.3.0 < 6.3.3
PaloaltonetworksGlobalprotect SwPlatformandroid Version >= 6.3.0 < 6.3.4
PaloaltonetworksGlobalprotect SwPlatformchrome Version >= 6.3.0 < 6.3.4
PaloaltonetworksGlobalprotect Version6.2.8 Update- SwPlatformmacos
PaloaltonetworksGlobalprotect Version6.2.8 Update- SwPlatformwindows
PaloaltonetworksGlobalprotect Version6.2.8 Updateh1 SwPlatformmacos
PaloaltonetworksGlobalprotect Version6.2.8 Updateh7 SwPlatformmacos
PaloaltonetworksGlobalprotect Version6.2.8 Updateh7 SwPlatformwindows
PaloaltonetworksGlobalprotect Version6.3.3 Update- SwPlatformlinux
PaloaltonetworksGlobalprotect Version6.3.3 Update- SwPlatformmacos
PaloaltonetworksGlobalprotect Version6.3.3 Update- SwPlatformuniversal_windows_platform
PaloaltonetworksGlobalprotect Version6.3.3 Update- SwPlatformwindows
PaloaltonetworksGlobalprotect Version6.3.3 Updateh1 SwPlatformlinux
PaloaltonetworksGlobalprotect Version6.3.3 Updateh1 SwPlatformmacos
PaloaltonetworksGlobalprotect Version6.3.3 Updateh2 SwPlatformlinux
PaloaltonetworksGlobalprotect Version6.3.3 Updateh2 SwPlatformmacos
PaloaltonetworksGlobalprotect Version6.3.3 Updateh2 SwPlatformwindows
PaloaltonetworksGlobalprotect Version6.3.3 Updateh3 SwPlatformmacos
PaloaltonetworksGlobalprotect Version6.3.3 Updateh3 SwPlatformwindows
PaloaltonetworksGlobalprotect Version6.3.3 Updateh4 SwPlatformmacos
PaloaltonetworksGlobalprotect Version6.3.3 Updateh4 SwPlatformwindows
PaloaltonetworksGlobalprotect Version6.3.3 Updateh6 SwPlatformmacos
PaloaltonetworksGlobalprotect Version6.3.3 Updateh6 SwPlatformwindows
PaloaltonetworksGlobalprotect Version6.3.3 Updateh7 SwPlatformmacos
PaloaltonetworksGlobalprotect Version6.3.3 Updateh7 SwPlatformwindows
PaloaltonetworksGlobalprotect Version6.3.3 Updateh8 SwPlatformmacos
PaloaltonetworksGlobalprotect Version6.3.3 Updateh8 SwPlatformwindows
PaloaltonetworksGlobalprotect Version6.3.3 Updateh9 SwPlatformuniversal_windows_platform
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.314
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
psirt@paloaltonetworks.com 5.2 0 0
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://security.paloaltonetworks.com/CVE-2026-0250
Vendor Advisory