Palo Alto Networks has released new GlobalProtect vulnerabilities and Prisma Access Agent issues affecting Windows, macOS, and Linux users. The announcements include 11 CVEs , with impacts ranging from control bypass and communication interception to local privilege escalation.

The updates were released on August 12th and primarily affect desktop versions. GlobalProtect on iOS, Android, and Chrome OS are exempt from several issues, but corporate device administrators need to check each operating system and version individually.
See also: Qilin ransomware: Exploiting GlobalProtect vulnerability
What does the new package reveal?
At the top of the list is CVE-2026-0296, a certificate validation flaw in the GlobalProtect application. According to the official advisory from Palo Alto Networks, an unauthenticated attacker with man-in-the-middle access could intercept or modify the application's communications. Traffic inside the VPN tunnel is not affected.
This vulnerability is rated Medium, with a CVSS-B of 7.4, and does not require any special configuration to be exposed. The company says it is not aware of any malicious exploits. There is no known workaround, so upgrading is the primary recommendation.
CVE -2026-0297 concerns a buffer overflow during the UDP tunnel handshake, while CVE-2026-0298 can lead to code execution via the Windows Pre-Logon Access Provider. The latter affects Windows, while versions 6.3 for Linux, macOS, iOS, Android, and Chrome OS are reported to be unaffected.

Who are affected by GlobalProtect vulnerabilities?
CVE -2026-0299 is one of the most significant GlobalProtect vulnerabilities, as it allows a local user to gain SYSTEM privileges on Windows or root on macOS and Linux. Palo Alto Networks rates it at CVSS-B 8.5, with no known active exploit reported.
In version 6.3, the fixes are 6.3.3-h14 (6.3.3-1121) for Windows and macOS and 6.3.3-h15 for Linux, with the latter expected to be available on August 28. Version 6.2 requires 6.2.8-h13 (6.2.8-1045) on Windows and macOS, while no unaffected version is listed for Linux yet. For the 6.0 series, the fix is 6.0.15, with an expected release date of August 31.
Meanwhile, CVE-2026-0295 concerns a race condition that could lead to privilege escalation on macOS. The iOS, Android, and Chrome OS app are not affected by this set of issues, but the variation per version means that a general "is GlobalProtect installed" check is not enough.
See also: Palo Alto: Active exploitation of GlobalProtect VPN vulnerability

Prisma Access Agent: separate update cycle
Four more reports concern the Prisma Access Agent. CVE-2026-0294 allows a local Windows or macOS user to execute code with elevated privileges, while CVE-2026-0292 and CVE-2026-0293 involve bypassing the security inspection and tamper protection mechanism in Windows.
The patch for these two operating systems is 26.3 or later, with an estimated availability on August 20. Linux, iOS, Android, and Chrome OS are not affected by CVE-2026-0294. Finally, CVE-2026-0291 concerns limited file deletion by an authenticated user on Linux and is fixed by version 26.2.2.
The remaining reports in the same publication concern PAN-OS and URL Filtering, not the GlobalProtect application. The aggregate picture shows that the GlobalProtect vulnerabilities are not a single bug, but different weaknesses with separate prerequisites and patch versions.

See also: CISA adds GlobalProtect vulnerability to KEV List
What should administrators do?
IT teams should record which workstations are running GlobalProtect and Prisma Access Agent, check the operating system and minor version, and schedule appropriate upgrades. Particular attention is needed on GlobalProtect 6.2 installations on Linux, where Palo Alto Networks has not yet released a patch for several of the vulnerabilities.
The SecNews technical team also recommends maintaining application logs and checking for unusual changes to VPN settings before the update cycle is complete. There is no indication that these GlobalProtect vulnerabilities are currently being used in attacks, but the lack of a workaround makes timely upgrades the safest option.
Organizations using affected versions should not expect a single “big” update: fixes are available by product, operating system, and release branch. The next critical date is the completion of the fixes that Palo Alto Networks has announced for August 20, 28, and 31.
