top of page

Palo Alto GlobalProtect hit by 5 vulnerabilities, enterprises should check now

On August 25, 2026, security researcher Martijn van Ramesdonk disclosed five vulnerabilities he had reported to Palo Alto Networks affecting GlobalProtect. Two issues were assigned under CVE-2026-0251 and can allow a low-privileged local user to escalate privileges to NT AUTHORITY\SYSTEM on Windows or root on macOS and Linux. Palo Alto Networks says it has not observed malicious exploitation.

GlobalProtect is a VPN and endpoint application used by enterprises to provide secure remote access to internal systems. Because the software runs with elevated privileges and sits close to an organization’s access layer, privilege escalation flaws can significantly increase the impact of an endpoint compromise.

An important distinction is that not all five findings have been confirmed by Palo Alto Networks as five separate CVEs. The most firmly validated issue is the set of local privilege escalation vulnerabilities tracked under CVE-2026-0251, while the remaining findings are primarily based on the researcher’s disclosure.

5-lo-hong-palo-alto-globalprotect
Warning 5 Palo Alto GlobalProtect vulnerabilities

What happened with Palo Alto GlobalProtect?

Security researcher Martijn van Ramesdonk said he submitted five GlobalProtect vulnerability reports to Palo Alto Networks beginning in early April 2026. According to Cyber Security News, two of the findings were incorporated into CVE-2026-0251, two other reports were considered outside the scope of the bug bounty program, and one remaining issue has not been fully disclosed because remediation is still pending.

Palo Alto Networks published its advisory for CVE-2026-0251 on May 13, 2026, and most recently updated it on June 2, 2026. The vendor confirmed that the vulnerabilities allow a local non-administrative user to escalate privileges to NT AUTHORITY\SYSTEM on Windows or root on macOS and Linux, enabling command execution with administrative privileges.

The main timeline is:

  • Early April 2026: the researcher said he submitted five findings to Palo Alto Networks.

  • May 13, 2026: Palo Alto Networks published CVE-2026-0251.

  • June 2, 2026: the advisory received its latest update.

  • August 25, 2026: information about all five findings and the disclosure process was published more broadly

How could these 5 Palo Alto GlobalProtect vulnerabilities affect enterprises?

CVE-2026-0251 is a local privilege escalation vulnerability. An attacker cannot simply exploit it remotely from the Internet to immediately gain SYSTEM or root access; the attacker must first be able to execute code or operate with a low-privileged account on the endpoint.

Even so, the flaw can be an important step in a broader attack chain. If malware, stolen credentials, or an attacker has already gained an initial foothold on a user device, the ability to escalate to administrative privileges can substantially expand their control.

Another detail disclosed by the researcher is the alleged ability to recover a user’s Active Directory password from an endpoint by abusing privileged GlobalProtect components. However, this capability is not described in Palo Alto Networks’ official CVE-2026-0251 advisory, so it should currently be treated as an independent research claim rather than a vendor-confirmed finding.

Which GlobalProtect versions should enterprises check?

GlobalProtect App on Windows, macOS, and Linux across multiple 6.0, 6.2, and 6.3 branches falls within the affected range. Android, iOS, Chrome OS, and the GlobalProtect UWP App are not affected by CVE-2026-0251, according to Palo Alto Networks. (Palo Alto Networks)

Platform

Versions to Check

Fixed Version

Windows

6.0.0–6.0.12

6.0.13 or later

Windows

6.2.0–6.2.8-h9

6.2.8-h10 or later

Windows

6.3.0–6.3.3-h10

6.3.3-h11 or later

macOS

6.0.0–6.0.12

6.0.13 or later

macOS

6.2.0–6.2.8-h9

6.2.8-h10 or later

macOS

6.3.0–6.3.3-h10

6.3.3-h11 or later

Linux

6.0.0–6.0.10

6.0.11 or later

Linux

6.2.0–6.2.9

Move to 6.3.3-h2 or later

Linux

6.3.0–6.3.3-h1

6.3.3-h2 or later

Palo Alto Networks states that there is no known workaround for CVE-2026-0251. Enterprises running affected builds should therefore plan to upgrade rather than rely on temporary configuration changes.

👉 Enterprises can refer to IPSIP’s guidance on vulnerability assessment and security testing to identify outdated software, unpatched systems, and remediation priorities

What should enterprises check and remediate now?

The first priority is to determine exactly which devices have GlobalProtect installed and which versions they are running. In environments with hundreds or thousands of endpoints, manually checking only a small sample can miss older systems, infrequently connected laptops, or special-purpose devices.

  •  Inventory all laptops, workstations, and servers running GlobalProtect App.

  •  Record the operating system and exact GlobalProtect version/build on each endpoint.

  •  Compare deployed versions against Palo Alto Networks’ CVE-2026-0251 advisory.

  •  Prioritize systems used by administrators, users with access to sensitive data, and frequent VPN users.

  •  Review endpoints that have previously shown malware activity, suspicious behavior, or compromised accounts.

  •  Enable or review EDR/XDR monitoring for processes executing with SYSTEM or root privileges.

  •  Centralize VPN, endpoint, and Active Directory logs to support investigation.

  •  Apply least privilege to reduce unnecessary user and administrative permissions.

  •  Review network segmentation so VPN endpoints do not automatically gain broad access to internal resources.

  •  After patching, verify the installed build and validate remediation on representative systems.

CVE-2026-0251 should not be confused with CVE-2026-0257, a separate PAN-OS/GlobalProtect issue that was associated with real-world intrusions involving Qilin ransomware.

👉IPSIP Vietnam previously analyzed the Palo Alto exploitation chain linked to Qilin ransomware deployment. Distinguishing between the two CVEs is important because one involves local privilege escalation while the other can enable unauthorized VPN access.

What does IPSIP Vietnam’s expert view highlight?

The attacker must already have low-level local access. CVE-2026-0251 is therefore best viewed as a post-compromise privilege escalation step, not as an initial Internet-facing entry point.

If an organization needs to verify how far a low-privileged account could escalate or move through the environment, IPSIP Vietnam’s Pentest service can use controlled testing scenarios to assess exploitability and real-world impact. Penetration testing does not replace patching, but it can help identify attack paths that remain after remediation.

Vietnamese enterprises that rely on VPN access for remote work should inventory GlobalProtect App deployments, update affected versions according to the vendor advisory, and review internal access controls. A compromised endpoint is far less likely to create a broader incident when user privileges, network segmentation, and security monitoring are properly enforced.

References

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
Logo-Zalo-Arc.webp
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page