Security Advisory

CVE-2026-0296

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-13 01:59:45
Last updated 2026-08-13 13:29:46
Assigner palo_alto
CVSS score 4.5
State PUBLISHED

Description

Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted. The GlobalProtect app on iOS, Android, and Chrome OS is not affected.