CVE-2026-0296

NONE
CVSS v3
CVSS v2
0.09% EPSS (exploit probability)
CWE-295CWE

Description

Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted.

The GlobalProtect app on iOS, Android, and Chrome OS is not affected.

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references